Cloudflare has introduced optional OAuth scopes for third-party applications, replacing all-or-nothing consent with task-based authorization. OAuth client owners can designate requested permissions as required or optional, enabling users to deselect individual optional scopes; tokens issued after authorization contain only the permissions the user approved. The feature is particularly intended to limit overprivileged access in AI-agent and Model Context Protocol (MCP) integrations, which may otherwise request permissions for every potential action.
The change applies only to scopes included in a given authorization request, and existing OAuth clients retain all-or-nothing behavior unless their owners opt in. Applications using optional scopes must inspect the scopes actually granted after authorization and safely reduce functionality where users decline permissions, rather than assuming a successful authorization supplied every requested privilege. Cloudflare reports that developers have created thousands of third-party OAuth apps and more than one million authorizations since launching its third-party app capability, and plans to extend role and scope coverage across most Cloudflare products.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The MCP 2026-07-28 specification preferred pre-registered clients and Client ID Metadata Documents while deprecating Dynamic Client Registration.
Cloudflare added OAuth scope customization that lets third-party OAuth client owners mark scopes as optional, allowing users to decline those permissions during consent. Tokens issued after consent contain only the scopes the user granted, and applications must inspect the granted scope set and handle partial access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
infoq.com
Open sourceblog.cloudflare.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.