Cloudflare announced Application Profiles, a mechanism intended to expand the concept of positive security from APIs to web applications. Rather than merely comparing requests against known attack signatures, the service learns the structure of successful requests and then checks how closely subsequent requests conform to that pattern.
The feature is based on Schema Profiles, which periodically analyze traffic to identify variables present in the path, query parameters, headers, cookies, and the structure of request bodies in JSON or form-encoded format. It also learns data types and constraints, such as integers, strings, booleans, arrays, UUID identifiers, and enumerated values, in addition to numeric ranges, string lengths, and character classes.
What changes in practice?
After a profile becomes available for a particular operation, Cloudflare activates a continuous validation layer on live traffic. If a path expects a UUID, or if the value of product_id must be an integer within a learned range, the system can record the request as nonconforming when a malformed, textual, or out-of-range value is received. This does not require the request to match a known signature for SQL injection, cross-site scripting, or remote code execution.
A nonconformance signal does not trigger an automatic action. The result is added to the request data, and teams can review it in Security Analytics before creating Security Rules for monitoring or blocking. Cloudflare provides a tab called Profile Analysis to display trends, conforming and nonconforming requests, and the location and reason for the violation. Rules can also be applied to the entire application or to specific paths, operations, and fields.
Learning requires human review
Learning runs weekly for each region using the latest successful traffic. The process requires at least 1,000 requests that returned a 2xx status code during the previous seven days to learn fields, and 10,000 requests to learn value boundaries. However, successful requests may include bots and scanning tools, so Cloudflare recommends starting in monitoring mode and reviewing the profile before enforcing it.
Nonconformance also does not necessarily indicate an attack; it may result from a new application release, a new client, or a valid but unfamiliar request. Profiles are updated weekly by adding new fields and removing fields that are no longer observed, with the ability to export them as OpenAPI v3 files and pin a version through Schema Validation.
Availability and limitations
Customers using API Security receive access to the feature, while Cloudflare has begun a closed beta program for invited Enterprise customers who do not use API Security. Joining the beta program does not mean that the feature will eventually be available under a specific plan.
- The feature supports paths, query parameters, headers, cookies, and JSON and form-encoded bodies.
- It currently does not support multipart forms, GraphQL, or XML.
- It can validate numeric and textual types, UUIDs, arrays, and enumerated values containing up to three values.
- It does not enforce uniqueness for repeated parameter names, does not learn required parameters, and does not block a request merely because it contains a new parameter.
Why does this development matter?
Cloudflare says that the spread of generative AI models makes it easier to produce, modify, and automatically test attack payloads, increasing the value of controls that define what is acceptable rather than chasing every known form of attack. The practical value here is not replacing managed WAF rules, but adding a layer that reduces the input space reaching application handlers.
The company is working on adding context and priority analysis, using models hosted on Workers AI to associate field names with their potential functions and suggest protective actions. However, these capabilities remain part of development plans or trials, and the accuracy of profiles depends on the quality and volume of the traffic from which they learn; therefore, gradual deployment and review before blocking remain essential requirements.