[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-oauth-scopes::en":3,"gloss-cluster-oauth-scopes::en":26,"gloss-next-oauth-scopes::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"oauth-scopes","integration","OAuth Scopes","OAuth scopes are the granular permissions a user grants an application when they connect it through OAuth — the specific list of things the app is allowed to do on their behalf. When you \"Sign in with Google\" and see a consent screen saying an app wants to \"read your calendar\" or \"send email as you,\" each of those is a scope. The authorization server issues an access token stamped with exactly those scopes and nothing more, so the connected app can read calendars but not delete files if that scope wasn't granted. For SaaS builders this cuts both ways. When you integrate a third-party tool, review the scopes it requests — an app asking for full account access when it only needs read access is a red flag and a breach-blast-radius problem. When you build an integration others connect to, request the least privilege you actually need; over-scoping scares off security-conscious customers and enlarges your liability. Well-designed APIs offer fine-grained, incremental scopes rather than one all-or-nothing permission.","OAuth scopes are the granular permissions a user grants an app — the consent screen's \"read your calendar\" list — and asking for fewer measurably lifts approval.",null,[11,14,17,20,23],{"slug":12,"name":13},"json-web-token","JSON Web Token (JWT)",{"slug":15,"name":16},"oauth","OAuth",{"slug":18,"name":19},"oauth-connection","OAuth Connection",{"slug":21,"name":22},"service-account","Service Account",{"slug":24,"name":25},"sso","Single Sign-On (SSO)",[27,31,34,37,40,43,47,50,53,54,57,60],{"slug":28,"category":5,"name":29,"updated_at":30},"backend-for-frontend","Backend for Frontend (BFF)","2026-08-24T02:46:38+00:00",{"slug":32,"category":5,"name":33,"updated_at":30},"concurrency-limit","Concurrency Limit",{"slug":35,"category":5,"name":36,"updated_at":30},"event-ordering","Event Ordering",{"slug":38,"category":5,"name":39,"updated_at":30},"field-mapping","Field Mapping",{"slug":41,"category":5,"name":42,"updated_at":30},"function-schema","Function Schema",{"slug":44,"category":5,"name":45,"updated_at":46},"grpc","gRPC","2026-08-24T02:46:37+00:00",{"slug":48,"category":5,"name":49,"updated_at":30},"integration-marketplace","Integration Marketplace",{"slug":51,"category":5,"name":52,"updated_at":30},"ip-allowlist","IP Allowlist",{"slug":12,"category":5,"name":13,"updated_at":30},{"slug":55,"category":5,"name":56,"updated_at":30},"mcp-server","MCP Server",{"slug":58,"category":5,"name":59,"updated_at":30},"mutual-tls","Mutual TLS (mTLS)",{"slug":61,"category":5,"name":62,"updated_at":30},"openapi-specification","OpenAPI Specification"]