TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/Articles/Cloudflare’s Task-Based OAuth Consent Turns All-or-Nothing Agent Permissions Into a Choice
Articles

Cloudflare’s Task-Based OAuth Consent Turns All-or-Nothing Agent Permissions Into a Choice

Cloudflare now lets developers mark OAuth scopes as optional, so a user authorizing an AI agent or MCP server can approve only the permissions it actually needs instead of the full request.

August 21, 2026 5 Min Read
44

For years, connecting a third-party app to a Cloudflare account meant one binary choice at the consent screen: approve everything the app asked for, or walk away. On August 20, 2026, Cloudflare shipped a fix aimed at a problem the company says its own permission model created: OAuth clients, MCP servers and AI agents in particular, that request broad access because they might theoretically need it, even when a given user only wants to grant a fraction of that access. The new feature, OAuth scope customization, lets developers mark individual scopes as optional so users can narrow a request instead of accepting or rejecting it wholesale.

Table Of Content

  • The all-or-nothing problem MCP servers made obvious
  • How optional scopes work
  • Scoping applies per request, not per client
  • Why this maps onto the confused deputy problem in MCP
  • What’s next

The all-or-nothing problem MCP servers made obvious

OAuth scopes are the mechanism that lets a user grant an application access to specific parts of an account instead of the whole thing: read a zone’s DNS records, write to a Workers KV namespace, and so on. Cloudflare already let OAuth clients request a subset of their configured scopes, but once a client made that request, the user had no way to narrow it further on the consent screen. As Cloudflare put it in its announcement, “If an application requested more access than a user was comfortable granting, their only options were to approve the full request, or deny outright.” Before this change, the only workaround was for each app developer to build a custom scope-selection screen of their own, ahead of handing the user off to Cloudflare’s consent flow. Cloudflare laid out the change in its own announcement post.

Cloudflare points to MCP servers, the Model Context Protocol’s standardized interface for connecting AI agents to external tools and data, as the clearest example of why that mattered: “An MCP server might request a broad set of permissions, because in theory an agent could use all of them. But most users would not want an agent to have that much access.”

How optional scopes work

With OAuth scope customization, client owners can mark specific scopes as required or optional when configuring an OAuth client. At authorization time, required scopes still show up as non-negotiable, but the user can deselect any of the optional ones before granting access. The configuration itself is a small addition to the client registration payload:

{
  "client_name": "ACME Corp",
  "redirect_uris": ["https://acme.org/oauth/callback"],
  "grant_types": ["authorization_code"],
  "response_types": ["code"],
  "token_endpoint_auth_method": "client_secret_basic",
  "scopes": ["user-details.read", "workers-scripts.write", "workers-kv-storage.write", "zone.read"],
  "optional_scopes": ["workers-kv-storage.write", "zone.read"]
}

In that example, user-details.read and workers-scripts.write stay required whenever they are part of a request, while the user decides whether to also grant workers-kv-storage.write and zone.read. If a request contains no optional scopes at all, the consent screen behaves exactly as it did before.

Scoping applies per request, not per client

One detail matters for anyone integrating this: required and optional status is evaluated against the scopes a specific authorization flow actually requests, not every scope ever configured on the client. Cloudflare’s own example makes this concrete. Take a client configured with four scopes, two required and two optional. If that client starts a flow requesting all four, the consent screen evaluates all four. If it later starts a flow requesting only two of them, only those two are considered, whether or not the other two are marked optional elsewhere in the client’s configuration.

That has a direct consequence for developers: they now need to check the granted scope set after exchanging the authorization code, rather than assuming a client received everything it asked for. Cloudflare frames this as good practice rather than a chore, arguing that an app or agent that operates gracefully within whatever narrower grant it receives is one users feel more comfortable authorizing in the first place.

None of this is a Cloudflare-specific quirk. RFC 6749, the OAuth 2.0 Authorization Framework, has always given authorization servers this latitude: “The authorization server MAY fully or partially ignore the scope requested by the client, based on the authorization server policy or the resource owner’s instructions. If the issued access token scope is different from the one requested by the client, the authorization server MUST include the ‘scope’ response parameter to inform the client of the actual scope granted.” Cloudflare’s change is a consent-screen interface built on top of a decade-old spec provision that most clients never had to reckon with, because until now, few consent flows actually put that provision in the user’s hands.

Why this maps onto the confused deputy problem in MCP

The timing lines up with something the Model Context Protocol’s own authorization specification already treats as a named risk. MCP’s spec, built on OAuth 2.1 and a set of supporting RFCs (RFC 8414 for authorization server metadata, RFC 7591 for dynamic client registration, RFC 9728 for protected resource metadata), devotes a dedicated section to what it calls the “Confused Deputy Problem”: “Attackers can exploit MCP servers acting as intermediaries to third-party APIs, leading to confused deputy vulnerabilities. By using stolen authorization codes, they can obtain access tokens without user consent.” The spec’s own mitigation is largely procedural: MCP proxy servers using static client IDs are required to obtain user consent for each dynamically registered client before forwarding it to a third-party authorization server. But the underlying exposure is the same one Cloudflare’s feature narrows from a different angle: an intermediary holding more access than any single interaction requires is a bigger blast radius if that intermediary is ever tricked, compromised, or simply misused.

sxz.io has covered adjacent pieces of this same problem already: how to isolate per-user OAuth tokens so one compromised session cannot reach another user’s data, how scoped authorization tokens fix the confused deputy problem inside an agent’s own tool-calling logic, and how Cloudflare’s Access for Workers pushes vibe-coded internal apps toward a zero-trust default instead of open-by-default. Optional OAuth scopes attack the same problem from yet another angle: instead of trusting the agent, or its developer, to request only the minimum, it puts the final narrowing decision in the hands of the person actually granting access. Readers who want the OAuth fundamentals underneath all of this, authorization codes, redirect URIs, and PKCE, can find a from-scratch walkthrough in sxz.io’s OAuth 2.0 authorization code flow tutorial.

What’s next

Cloudflare says it is expanding optional-scope support over the next few weeks to cover nearly every Cloudflare product, meaning more API token roles, account membership options, and OAuth scopes will get the same treatment. The company credited two of its interns, Miller Vargas, a University of Texas at Austin senior studying computer science and math, and José Enrique Rodriguez, a Universidad Panamericana engineering senior, with building the feature. For developers, this is a configuration change rather than a new integration: existing Cloudflare Third Party OAuth clients can start marking scopes optional today.

The broader pattern is hard to miss. As more of what touches an account is an agent rather than a human clicking through a UI, the definition of “enough access” keeps shrinking, and the tooling for enforcing that shrinkage is having to catch up fast.

Tags:

AI AgentsAPI SecurityAuthorizationCloudflareMCP

Share

Jockeys in yellow, blue, and red silks urge their horses forward in a tightly bunched sprint down a dirt racetrack, with the lead horse just a nose ahead of the pack.
Previous Post

OpenAI Narrows Anthropic’s Business AI Lead, New Ramp Data Shows

Dew drops outlining the threads and junctions of a spider web against a dark background, a natural example of nodes connected by relationships
Next Post

How to Build a Dependency Graph With Neo4j and Python to Trace Vulnerable Packages

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Blue-lit server racks in a modern data center, illustrating the compute infrastructure behind the AI boom.
Articles

The AI Boom Is Spending Real Money Before Proving Real Returns

June 7, 2026
Technician working with a laptop beside server racks, representing enterprise AI retrieval infrastructure
Articles

Google’s Agentic RAG Push Makes Enterprise AI Less of a One-Shot Guess

June 7, 2026
A person with a laptop and smartphone, representing digital attention and AI-assisted work
Articles

AI Chatbots Are Making Attention a Design Problem

June 7, 2026
A customer-support representative wearing a headset against a dark studio background.
Articles

The Meta AI Support Hack Was a Plain Old Authorization Failure

June 7, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026