Prompt
oauth consent screen scopes
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
In OAuth, consent screen scopes are the permissions your app asks the user to grant during login/authorization.
What scopes do
Scopes tell the authorization server:
- what data your app wants to access
- what actions it wants to perform
The consent screen shows the user a list like:
- Read your profile
- View your email address
- Access your calendar
Why they matter
Scopes help users make an informed choice before approving access. They also enforce least privilege—your app should request only what it truly needs.
Common examples
openid— use OpenID Connect sign-inemail— access email addressprofile— access basic profile infooffline_access— request refresh tokens- Google example:
https://www.googleapis.com/auth/calendar.readonly
Best practices
- Request the fewest scopes possible
- Ask for additional scopes only when needed
- Use incremental authorization if supported
- Make sure the consent screen text clearly explains why each permission is needed
If you want, I can also explain:
- how scopes differ from roles/permissions, or
- how to choose scopes for Google / Microsoft / GitHub OAuth.