Cloudflare’s changelog says Wrangler and the Cloudflare API MCP server now let users edit optional OAuth permissions during authorization rather than approve every requested scope. Required scopes remain selected; declining optional scopes narrows access, and a command or tool call needing a declined scope requires reauthorization to grant it. This establishes a consent and permissions change for these two clients, not evidence that broader agent-security risks are solved.
Cloudflare’s new consent controls converge with Scott’s MCP least-privilege position and provide a concrete integration example for his agent-readable credential health and decision-backed resumption patterns: declined scopes become authorization blockers requiring reauthorization, not blind retries. This offers a bounded publishing opportunity around containment versus action provenance—not evidence of his stronger per-action authorization model; the supplied hits establish neither Scott’s use of these two clients nor prior radar coverage of this specific change.
ip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebookip:framework.agent-provenance-stackdev:concept.agent-readable-credential-healthdev:concept.decision-backed-agent-resumptionradar:concept.agent-authorizationradar:concept.mcp-securityradar:concept.cloudflare
queries asked of Scott's wikis
- agent tool authorization least privilege
- MCP OAuth scope enforcement
- Cloudflare Wrangler deployment workflows
- agent permission escalation human approval
- coding harness reauthorization missing permissions
now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 1226h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion