From all-or-nothing to task-based OAuth consent
Blog post from Cloudflare
Cloudflare has introduced OAuth scope customization, allowing developers to designate certain requested permissions as optional so users can deselect them during authorization rather than accepting an all-or-nothing access request. The feature addresses increasingly granular permission needs for SaaS integrations, internal tools, CLIs, and AI agents such as MCP servers, while preserving existing behavior for clients that do not enable optional scopes. Required and optional status is evaluated only among scopes requested in each individual authorization flow, keeping consent screens focused on the access needed for a particular task. When users decline optional permissions, issued access tokens include only the scopes granted, requiring developers to design applications that can function safely with partial authorization. Cloudflare also plans to expand account- and zone-level roles, API token roles, membership options, and OAuth scopes across nearly all of its products, further supporting fine-grained access control.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 2 | 8,107 | 809 | 199 | -26% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.