What Does This OAuth Grant Actually Allow?
Decode connected-app permissions into plain English
Most Microsoft 365, Google Workspace, and Salesforce admin consoles
have a page listing connected third-party apps and the scopes each
one was granted. The scope names themselves — Mail.ReadWrite,
Directory.Read.All, gmail.modify — aren't
self-explanatory. Select the platform and the scopes a connected app
has, and this shows what that combination actually grants.
Platform
Each platform has its own scope naming — select one to see its common scopes.
For the bigger picture — where this fits relative to what your secrets manager or CNAPP already covers — the risk self-check's Section D covers SaaS-to-SaaS OAuth as its own category.
Export this decode. Download these results as a PDF — useful for documenting what a connected app was found to have access to. Requires a free subscription.