Account API token creation is no longer limited to Super Administrators. Members with the API Token Provisioning role can now create Account API tokens via the Dashboard, API, Terraform, or CF CLI, making it easier for developers and platform teams to provision credentials without depending on a Super Administrator for Account API Token Provisioning.

- Delegated creation: Members with the API Token Provisioning role can create Account API tokens from the dashboard. Administrators can grant this role through the dashboard, API, or Terraform.
- OAuth support for token creation: OAuth clients that request the
account_api_tokens:createscope, starting with Cloudflare CLI, can create Account API tokens. - Account API token permissions limited to the creator’s access at creation time: Members can only create an Account API Token using the permissions they already have. For OAuth-created tokens, permissions are also limited to the scopes granted during authorization.
- Creator attribution and visibility: Account API tokens now include creator metadata. Super Administrators and Administrators can view all Account API tokens in an account, while members with the API Token Provisioning role can only view tokens they created.
For more information, refer to Account API tokens, Create tokens via API, and Roles.
Source: Cloudflare


