{
  "id": 5057180,
  "title": "Cloudflare Adds Optional OAuth Scopes, Letting Developers Mark What Users May Decline",
  "url": "https://urgent.news/2026/09/02/cloudflare-adds-optional-oauth-scopes-letting-developers-mark-what",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-02T09:07:00.000Z",
  "source": {
    "name": "InfoQ",
    "slug": "infoq",
    "url": "https://www.infoq.com/news/2026/09/cloudflare-optional-oauth-scopes/"
  },
  "original_language": "en",
  "account": "Cloudflare has introduced optional OAuth scopes, enabling users to select specific permissions during the consent screen. This feature addresses the issue faced by agents, which often require broad sets of permissions, causing users to decline an application's full request due to concerns over extensive access. By marking scopes as optional, developers can now request only the necessary permissions, allowing users to deselect any that are not required. This change aims to provide a more granular consent process, improving user experience and reducing the risk of applications requesting unnecessary permissions. When a user declines an optional scope, the access token issued will only contain the granted permissions, prompting applications to adjust their functionality accordingly. Cloudflare's approach emphasizes developer control over which permissions may be dropped, while still placing the decision in the user's hands during the consent process.",
  "summary": "Cloudflare has added optional OAuth scopes, letting client owners mark which permissions users may deselect at consent. The company names MCP servers as the motivating case, since agents request the union of everything they might do. Partial consent exists elsewhere, but developer control over which scopes are droppable does not. By Steef-Jan Wiggers",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}