R2 Data Catalog now accepts read-only API tokens, so query engines and clients that only read data no longer need a read-write token. Previously, every catalog operation required an Admin Read & Write token, which meant read-only clients were granted more access than they needed. You can now authenticate your Iceberg engine based on your workload: Read-only operations (such as listing namespaces, loading tables, and querying data) work with an Admin Read only token (R2 Data Catalog read and R2 storage read).
R2 - R2 Data Catalog now supports read-only API tokens
calendar_today
July 13, 2026
domain
cloudflare