← Back to feed
Securitycloudflare_blogAlphaLab AI score 26/100

Cloudflare OAuth adds optional scopes for granular user consent

Cloudflare has updated its OAuth implementation to allow optional scopes, giving users finer control over application permissions. Since June, developers have created thousands of third-party OAuth apps on Cloudflare with over a million authorizations. Previously, users faced an all-or-nothing choice when approving OAuth access requests - either granting all requested permissions or rejecting them entirely. The new optional scopes feature lets client owners mark certain permissions as non-mandatory, enabling users to selectively grant only specific access rights while maintaining required functionality. This change supports Cloudflare's growing ecosystem of SaaS integrations, internal tools, and CLI applications while maintaining OAuth's secure delegated access model without requiring password sharing.

Original source← Back to feed