Non-Human Identity Software
an independent guide to NHI security software
Subscribe
Tool

What Does This OAuth Grant Actually Allow?

Decode connected-app permissions into plain English

Most Microsoft 365, Google Workspace, and Salesforce admin consoles have a page listing connected third-party apps and the scopes each one was granted. The scope names themselves — Mail.ReadWrite, Directory.Read.All, gmail.modify — aren't self-explanatory. Select the platform and the scopes a connected app has, and this shows what that combination actually grants.

Platform

Each platform has its own scope naming — select one to see its common scopes.

Overall risk for this combination
Select scopes below

For the bigger picture — where this fits relative to what your secrets manager or CNAPP already covers — the risk self-check's Section D covers SaaS-to-SaaS OAuth as its own category.

Export this decode. Download these results as a PDF — useful for documenting what a connected app was found to have access to. Requires a free subscription.

See what's in the paid edition →