Breaking
SickKids data breach exposes employee and job applicant informationGitLab’s critical CVE-2026-19478 is under active exploitation within days of disclosure.Khazanah affirms governance push after third-quarter board meetingQR code payments launched for ShopeePay users in ChinaBanjarbaru delays school start times as haze worsensLuxury sales drop more than 10% in China as tax crackdown bitesCDL net profit surges 230.7% in first half on Lumina Grand recognitionTrade Minister sets US$25 billion Trade Expo Indonesia 2026 targetTeladan Group swings to RM9.31 million profit in 2QFY2026 on higher progressive billingsAI Living @ i-City to launch in Shah Alam with four agenciesNevada approves 8,000 robotaxis for Tesla, Uber and WaymoAI data startup Micro1 reaches $500M gross run rate amid AI training boomMan jailed and caned for stabbing Singapore priest during communionEmployee of town council managing agent charged with corruption offencesDialog Group rises 2% as oil price boost lifts earnings hopesOAuth apps on Cloudflare hit 1,000 mark since June with over 1 million user consentsCISA issues logging guidance for US federal agencies ahead of 2026 deadlineRussian missile strikes kill 17 in Kyiv, Guterres demands ceasefireGaza shelter crisis deepens as Israeli strikes and aid curbs bitePrince Harry, Meghan and children return to Britain: key factsSickKids data breach exposes employee and job applicant informationGitLab’s critical CVE-2026-19478 is under active exploitation within days of disclosure.Khazanah affirms governance push after third-quarter board meetingQR code payments launched for ShopeePay users in ChinaBanjarbaru delays school start times as haze worsensLuxury sales drop more than 10% in China as tax crackdown bitesCDL net profit surges 230.7% in first half on Lumina Grand recognitionTrade Minister sets US$25 billion Trade Expo Indonesia 2026 targetTeladan Group swings to RM9.31 million profit in 2QFY2026 on higher progressive billingsAI Living @ i-City to launch in Shah Alam with four agenciesNevada approves 8,000 robotaxis for Tesla, Uber and WaymoAI data startup Micro1 reaches $500M gross run rate amid AI training boomMan jailed and caned for stabbing Singapore priest during communionEmployee of town council managing agent charged with corruption offencesDialog Group rises 2% as oil price boost lifts earnings hopesOAuth apps on Cloudflare hit 1,000 mark since June with over 1 million user consentsCISA issues logging guidance for US federal agencies ahead of 2026 deadlineRussian missile strikes kill 17 in Kyiv, Guterres demands ceasefireGaza shelter crisis deepens as Israeli strikes and aid curbs bitePrince Harry, Meghan and children return to Britain: key facts
Economy

OAuth apps on Cloudflare hit 1,000 mark since June with over 1 million user consents

Cloudflare Inc said it now hosts more than 1,000 third-party OAuth applications on its platform, with over 1 million user authorisations since June.

Source: Cloudflare Blog · August 21, 2026 at 7:41 AM · AI-assisted report

Single-source
OAuth apps on Cloudflare hit 1,000 mark since June with over 1 million user consents
Photo: LBJLibraryNow via flickr (PDM)

KUALA LUMPUR, 21 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

Cloudflare Inc said it now hosts more than 1,000 third-party OAuth applications on its platform, with over 1 million user authorisations since June.

Market Impact

The cloud-services provider introduced optional OAuth scope customisation on Tuesday so users can accept only the permissions they need rather than an all-or-nothing choice.

Client owners can mark specific scopes as optional when configuring an OAuth client. The updated consent screen then lets users deselect those scopes. Developers must check the granted scopes after exchanging the authorisation code, rather than assuming the entire requested set was approved.

For example, a client configured with user-details.read, workers-scripts.write, workers-kv-storage.write and zone.read can mark the last two as optional. If the app later requests only workers-scripts.write and zone.read, the consent screen shows only those two scopes. Required scopes remain mandatory if included in the request.

The change keeps the consent screen focused on the task at hand instead of exposing every capability the application could ever request. Developers who opt into the feature retain existing behaviour if they do not designate any scopes as optional.

Cloudflare said it is also expanding account and zone-level role controls across nearly every product. Over the coming weeks, the company will add more API token roles, account membership options and OAuth scopes to give customers finer-grained access controls.

The update follows a trend in the developer ecosystem toward more granular security models. According to Cloudflare, the move aligns with increasing demand from security-conscious users for better control over third-party access.

Reporting based on Cloudflare Blog. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.