# Cloudflare removes old Tunnel route endpoints — some Zero Trust automation now needs migration

Cloudflare's October 5 cutoff removes CIDR-encoded Zero Trust route endpoints and strips connection details from Tunnel and Mesh list/get responses. Direct API consumers need to move to route IDs and dedicated connections endpoints.

The break is narrow but concrete: scripts and CI/CD calling the old route paths can fail, while monitoring code that expected `connections` inline must fetch it separately.

- Status: Active
- Published: 2026-10-05T21:55:24+13:00
- Updated: 2026-10-05T21:55:24+13:00
- Categories: Cloud & Infrastructure, Cloud Platforms, Deployment & DevOps
- Tags: API deprecation, API migration, Cloudflare, Cloudflare Tunnel
- Canonical HTML: https://beyondthe.news/dossiers/cloudflare-tunnel-zero-trust-route-api-connections-removal-october-2026

## What changed

On October 5, 2026, Cloudflare removes three CIDR-encoded Zero Trust Networks route endpoints and removes the `connections` array from Cloudflare Tunnel and Cloudflare Mesh list/get responses. Route creation now sends the network and tunnel ID in the request body; updates and deletes identify routes by `route_id`. Connection details move to dedicated per-tunnel or per-Mesh-node connections endpoints.

## Why it matters

This is an API-shape break rather than a cosmetic deprecation. Builders with scripts, backend services or CI/CD that directly call the old CIDR route paths need to migrate, and dashboards or monitoring code that parses connection state from tunnel objects need an extra API call. Cloudflare says current `cloudflared` and Terraform users are insulated from the connections-field change, but direct consumers are not.

## Route identity moves from the CIDR to a resource ID

The old API encoded the network directly into the request path. The replacement treats the route as a normal resource: create it with the network and tunnel ID in the body, retain its `route_id`, then use that ID for later updates or deletion. Automation that constructed URLs from CIDRs therefore needs more than a path rename.

## Connection state becomes an explicit second lookup

Cloudflare is also shrinking Tunnel and Mesh list/get responses by removing their embedded `connections` arrays. Code that uses those responses for connector health, dashboards or inventory must query the dedicated connections endpoint when it needs that detail. Cloudflare says `cloudflared` and its Terraform provider do not depend on the removed field.

## Key details

- Removed route operations are the CIDR-encoded create, update and delete paths under `/teamnet/routes/network/{ip_network_encoded}`.
- Replacement route operations use `/teamnet/routes` for creation and `/teamnet/routes/{route_id}` for update and delete.
- Tunnel and Mesh list/get responses no longer include the `connections` array.
- Connection details remain available through dedicated `/connections` endpoints.
- Cloudflare advises direct API users to capture route IDs, update scripts and CI/CD, and upgrade `cloudflared` if using its tunnel route commands.

## Builder takeaways

- Search direct Cloudflare API integrations for `/teamnet/routes/network/` and migrate them to route-ID operations.
- Check monitoring and inventory code for assumptions that `connections` is present on Tunnel or Mesh objects.
- If route automation uses `cloudflared tunnel route ip`, upgrade `cloudflared`; if it uses Terraform, keep the Cloudflare provider and route resource current.

## What to watch

- Post-cutoff reports of broken custom Tunnel or Zero Trust automation.
- Whether Cloudflare publishes additional compatibility or migration guidance after the removal.

## Uncertainties

- Cloudflare's changelog documents the October 5 removal but does not quantify how many direct API consumers still use the deprecated shapes.
- The documentation describes the migration contract; it does not provide independent post-cutoff breakage data.

## Sources

- [Zero Trust Networks route endpoints and Cloudflare Tunnel connections field retiring on October 5, 2026](https://developers.cloudflare.com/changelog/product/cloudflare-tunnel-sase/) — Cloudflare · primary documentation · 2026-07-09T00:00:00+12:00. Documents the October 5 removal, exact deprecated and replacement endpoints, connections-field removal and required migration steps.

