Prompt
What scopes do I actually need for Google OAuth sign in?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
For Google OAuth sign-in, you usually need very few scopes.
Minimum scopes
If your only goal is to identify the user and get basic profile info, the standard scopes are:
openidemailprofile
These are the typical scopes for Google Sign-In / OpenID Connect.
What each gives you
openid: tells Google you’re using OpenID Connect and allows an ID tokenemail: lets you read the user’s email addressprofile: lets you read basic profile data like name and picture
If you only need sign-in
In many cases, you don’t even need to request more than these.
If you’re using Google just to authenticate a user, these are enough.
Avoid extra scopes unless you need them
Don’t request things like:
- Google Drive
- Calendar
- Gmail
- Contacts
unless your app actually needs access to those APIs. Extra scopes increase consent friction and can trigger Google verification requirements.
Common examples
Basic login
openid email profile
If you only want email and don’t care about profile
openid email
Important note
If you’re using Google OAuth just for login, the ID token is what you typically use to authenticate the user on your backend, not access tokens for Google APIs.
If you want, I can also show:
- the exact scopes to use for web / mobile / SPA, or
- the difference between OAuth scopes and Google Sign-In identity claims.
Brands