<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cloudflare-adds-optional-oauth-scopes-letting-developers-mark-what-users-may-decline-c0uhkqtsf" -->

---
title: Cloudflare Adds Optional OAuth Scopes, Letting...
description: Cloudflare now lets OAuth client owners mark specific scopes as optional, so users can deselect individual permissions on the consent screen instead of an...
canonical: https://daily.dev/posts/cloudflare-adds-optional-oauth-scopes-letting-developers-mark-what-users-may-decline-c0uhkqtsf
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Cloudflare Adds Optional OAuth Scopes, Letting Developers Mark What Users May Decline | daily.dev
og:description: Cloudflare now lets OAuth client owners mark specific scopes as optional, so users can deselect individual permissions on the consent screen instead of an...
og:url: https://daily.dev/posts/cloudflare-adds-optional-oauth-scopes-letting-developers-mark-what-users-may-decline-c0uhkqtsf
og:image: https://api.daily.dev/og/posts/C0uHkQTSF.png
og:image:alt: Cloudflare Adds Optional OAuth Scopes, Letting Developers Mark What Users May Decline
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Cloudflare Adds Optional OAuth Scopes, Letting Developers Mark What Users May Decline

**[InfoQ](https://daily.dev/sources/infoq)** · 5 min read · 0 upvotes · 0 comments

## Summary

Cloudflare now lets OAuth client owners mark specific scopes as optional, so users can deselect individual permissions on the consent screen instead of an all-or-nothing approve/deny. The motivating case is MCP servers and AI agents, which often request the union of every permission they might ever need, leaving users to either approve everything or bounce. Client owners configure an optional_scopes array alongside required scopes; required scopes cannot be dropped, while optional ones can be removed by the user, and the resulting access token reflects only what was granted. This builds on existing RFC 6749 latitude for narrower-than-requested tokens, joining similar partial-consent mechanisms from GitHub, Google, and Microsoft Entra, though Cloudflare's addition is developer control over which scopes are droppable. Developers must now inspect the scope in the token response and degrade gracefully rather than assume full access, since code expecting the old all-or-nothing behavior can now hit authorization errors on calls it previously could make.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.infoq.com/news/2026/09/cloudflare-optional-oauth-scopes>

## Questions this post answers

### What are optional OAuth scopes in Cloudflare and how do I configure them?

Cloudflare lets OAuth client owners mark specific scopes as droppable by users at consent time, using an optional_scopes array listed alongside the client's full scopes array. Scopes not included in optional_scopes are treated as required and cannot be removed by the user. Required and optional scopes are evaluated only against the scopes requested in a given authorization flow, not the client's full configured list.

_Teams wiring up OAuth consent for agents can track platform changes like this via daily.dev._

### Why do MCP servers request such broad OAuth permission sets from users?

MCP servers often request every scope an AI agent could theoretically need, because the agent's exact actions aren't known in advance, exposing the union of everything it might ever do. For example, an agent comparing product inventory doesn't need price-change permission, and one checking order status doesn't need refund authority, yet both get bundled into a single consent request. This forces developers to choose between minimal scopes that break advanced use or broad scopes that scare users off the consent screen.

_Developers designing agent permission models can follow this tradeoff discussion on daily.dev._

### How should an application handle it when a user removes an optional OAuth scope?

Applications should inspect the scope parameter in the token response after the authorization code exchange rather than assuming the full requested set was granted, since a deselected optional scope means the token carries only what remains. Cloudflare's guidance is to degrade gracefully: disable the affected feature and tell the user, instead of surfacing a raw 403 error that looks like a broken integration.

_Engineers hardening OAuth clients against partial consent can keep up with guidance like this on daily.dev._

## Similar posts on daily.dev

- [From all-or-nothing to task-based OAuth consent](https://daily.dev/posts/from-all-or-nothing-to-task-based-oauth-consent-t9bk34fln) · Cloudflare · 2 upvotes · 0 comments
- [Securing non-human identities: automated revocation, OAuth, and scoped permissions](https://daily.dev/posts/securing-non-human-identities-automated-revocation-oauth-and-scoped-permissions-arfnwgtex) · Cloudflare · 1 upvotes · 0 comments
- [Unlocking the Cloudflare app ecosystem with OAuth for all](https://daily.dev/posts/unlocking-the-cloudflare-app-ecosystem-with-oauth-for-all-tkqsqak0n) · Cloudflare · 10 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#authentication](https://daily.dev/tags/authentication), [#mcp](https://daily.dev/tags/mcp), [#cloudflare](https://daily.dev/tags/cloudflare), [#oauth](https://daily.dev/tags/oauth)

[View this post on daily.dev](https://daily.dev/posts/cloudflare-adds-optional-oauth-scopes-letting-developers-mark-what-users-may-decline-c0uhkqtsf)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Cloudflare Adds Optional OAuth Scopes, Letting Developers Mark What Users May Decline","url":"https://daily.dev/posts/cloudflare-adds-optional-oauth-scopes-letting-developers-mark-what-users-may-decline-c0uhkqtsf","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cloudflare-adds-optional-oauth-scopes-letting-developers-mark-what-users-may-decline-c0uhkqtsf"},"datePublished":"2026-09-02T09:26:24.602Z","dateModified":"2026-09-02T09:26:49.545Z","description":"Cloudflare now lets OAuth client owners mark specific scopes as optional, so users can deselect individual permissions on the consent screen instead of an...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ad713c59cfe4e12ba2c1a48841f41532?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ad713c59cfe4e12ba2c1a48841f41532?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"InfoQ","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"InfoQ","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/afc3bced3e1e4b188dd9127017a60e0c","url":"https://daily.dev/sources/infoq"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/cloudflare-adds-optional-oauth-scopes-letting-developers-mark-what-users-may-decline-c0uhkqtsf","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,authentication,mcp,cloudflare,oauth","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"InfoQ","item":"https://daily.dev/sources/infoq"},{"@type":"ListItem","position":3,"name":"Cloudflare Adds Optional OAuth Scopes, Letting Developers Mark What Users May Decline"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/cloudflare-adds-optional-oauth-scopes-letting-developers-mark-what-users-may-decline-c0uhkqtsf#faq","mainEntity":[{"@type":"Question","name":"What are optional OAuth scopes in Cloudflare and how do I configure them?","acceptedAnswer":{"@type":"Answer","text":"Cloudflare lets OAuth client owners mark specific scopes as droppable by users at consent time, using an optional_scopes array listed alongside the client's full scopes array. Scopes not included in optional_scopes are treated as required and cannot be removed by the user. Required and optional scopes are evaluated only against the scopes requested in a given authorization flow, not the client's full configured list. Teams wiring up OAuth consent for agents can track platform changes like this via daily.dev."}},{"@type":"Question","name":"Why do MCP servers request such broad OAuth permission sets from users?","acceptedAnswer":{"@type":"Answer","text":"MCP servers often request every scope an AI agent could theoretically need, because the agent's exact actions aren't known in advance, exposing the union of everything it might ever do. For example, an agent comparing product inventory doesn't need price-change permission, and one checking order status doesn't need refund authority, yet both get bundled into a single consent request. This forces developers to choose between minimal scopes that break advanced use or broad scopes that scare users off the consent screen. Developers designing agent permission models can follow this tradeoff discussion on daily.dev."}},{"@type":"Question","name":"How should an application handle it when a user removes an optional OAuth scope?","acceptedAnswer":{"@type":"Answer","text":"Applications should inspect the scope parameter in the token response after the authorization code exchange rather than assuming the full requested set was granted, since a deselected optional scope means the token carries only what remains. Cloudflare's guidance is to degrade gracefully: disable the affected feature and tell the user, instead of surfacing a raw 403 error that looks like a broken integration. Engineers hardening OAuth clients against partial consent can keep up with guidance like this on daily.dev."}}]}
```

