2026-10-11 16:37 UTC

Cloudflare says Wrangler and its API MCP server now let users decline optional OAuth scopes, enabling narrower tool permissions while requiring reauthorization for operations that need declined scopes.

state: seedheat: lowuncertainty: mediumconvergesscott: mediummcp agentic-security oauthCloudflare

What is this?

Cloudflare’s changelog says Wrangler and the Cloudflare API MCP server now let users edit optional OAuth permissions during authorization rather than approve every requested scope. Required scopes remain selected; declining optional scopes narrows access, and a command or tool call needing a declined scope requires reauthorization to grant it. This establishes a consent and permissions change for these two clients, not evidence that broader agent-security risks are solved.

Why it matters to Scott

Cloudflare’s new consent controls converge with Scott’s MCP least-privilege position and provide a concrete integration example for his agent-readable credential health and decision-backed resumption patterns: declined scopes become authorization blockers requiring reauthorization, not blind retries. This offers a bounded publishing opportunity around containment versus action provenance—not evidence of his stronger per-action authorization model; the supplied hits establish neither Scott’s use of these two clients nor prior radar coverage of this specific change.
ip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebookip:framework.agent-provenance-stackdev:concept.agent-readable-credential-healthdev:concept.decision-backed-agent-resumptionradar:concept.agent-authorizationradar:concept.mcp-securityradar:concept.cloudflare
queries asked of Scott's wikis
  • agent tool authorization least privilege
  • MCP OAuth scope enforcement
  • Cloudflare Wrangler deployment workflows
  • agent permission escalation human approval
  • coding harness reauthorization missing permissions

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 1226h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

08-21 14:00⭐ origin echo-reconstructedWrangler and the Cloudflare API MCP server now use optional OAuth scopes; users can edit granted permissions during authorization, required
Cloudflare on blog (echo) · attributed from hn.story.49684332
—
09-13 14:22first on hacker news · published · +552.4hChoose OAuth Scopes for Wrangler and the Cloudflare API MCP Server
cs1996
—
09-13 14:22amplified on hacker news 👑hn.story.49684332
cs1996
peak 1 · 1 comments · 98% of case engagement
09-13 15:20our radar first saw it · +553.4hdiscovery anchor: hn.story.49684332—

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnChoose OAuth Scopes for Wrangler and the Cloudflare API MCP Server
Retrieved article excerpt

Open article · Retrieved 2026-09-13T15:22:33.050898+00:00

August 22, 2026

## Choose OAuth scopes for Wrangler and the Cloudflare API MCP server

[Agents](https://developers.cloudflare.com/agents/)[Workers](https://developers.cloudflare.com/workers/)

Wrangler and the [Cloudflare API MCP server](https://developers.cloudflare.com/agents/model-context-protocol/cloudflare/servers-for-cloudflare/) now use optional OAuth scopes. During authorization, you can choose which optional scopes to grant instead of approving every scope requested by each client.

The consent dialog now includes the option to edit the permissions you grant to Wrangler or the Cloudflare API MCP server:

OAuth consent dialog with an Edit Permissions button

You can then choose which specific permissions to grant:

OAuth permission editor with controls for individual scopes

Required scopes remain selected. Choosing fewer optional scopes limits each tool's access to the permissions needed for your workflow.

If a command or tool call needs a scope that you declined, reauthorize the client and grant that scope.

For more information, refer to [`wrangler login`](https://developers.cloudflare.com/workers/wrangler/commands/general/#login) and [Edit optional permissions](https://developers.cloudflare.com/fundamentals/oauth/authorizing-an-application/#edit-optional-permissions).
cs199611
🟧 echo.blog ⭐Wrangler and the Cloudflare API MCP server now use optional OAuth scopes; users can edit granted permissions during authorization, required Cloudflare——

Interpretation history

Decision trace