Why Granting an AI Agent Broad OAuth Scopes Is a Mistake
Broad OAuth scopes turn a helpful AI agent into a standing liability. Here is how to grant only what the task in front of you actually needs.
Why Granting an AI Agent Broad OAuth Scopes Is a Mistake
Granting an AI agent broad OAuth scopes is a mistake because most integrations ask for far more access than the task in front of them needs, and once granted that access sits there indefinitely, waiting for a prompt injection, a bug, or a compromised session to use it. The fix is not refusing to connect agents to your accounts. It is treating scope as a budget you spend deliberately, one permission at a time.
This is not a hypothetical. On September 14, 2026, screenshots surfaced of an unreleased Claude Money feature in the Claude iOS app: an onboarding screen inviting users to link bank accounts so Claude can answer questions about spending and budgets. Anthropic has not officially announced the feature or confirmed a launch date. What is notable is not the leak itself, it is the design choice visible in the screenshots: a dedicated Money section, separate from general chat, suggesting a deliberately scoped integration rather than a blanket "access everything" grant.
That distinction, narrow purpose-built access versus broad standing access, is the entire subject of this post.
What an OAuth scope actually controls
An OAuth scope is a string a service checks before letting an application touch a specific piece of your account. `calendar.readonly` lets an app see your events. `calendar.events` lets it create and delete them too. `gmail.send` lets an app send email as you, permanently, until you revoke it.
Scopes are not one setting called "access." They are a list, and every provider lets you request a lot fewer of them than most integrations do.
Why AI agents make this worse than a normal app integration
A traditional app requests a scope once, at install, and a human reviewed what it does before shipping it. An AI agent's actions are generated at runtime, from a prompt, which means the thing deciding how to use a scope is not a fixed program a developer tested. It is a model responding to whatever text it was just given, including text an attacker put there.
This is the mechanism behind every "is it safe to let an AI agent access your X" question on this blog, from email inbox access to managing your passwords. The common thread underneath all of them is scope. An agent with `gmail.readonly` that gets prompt-injected by a malicious email can, at worst, leak what it already read. An agent with `gmail.send` and `gmail.modify` that gets prompt-injected can send email as you and delete the evidence.
The three questions that decide a scope request
Ask these before accepting any OAuth consent screen for an agent, not after:
**Does the task need read or write?** Most "helpful assistant" use cases (summarizing, answering questions, flagging patterns) need read-only. Reach for write scopes only when the agent's actual job is to take action, and even then, scope the action narrowly. Anthropic's leaked Claude Money interface, from the public screenshots, appears to be exactly this: a read-only financial view, not a payments feature.
**Is the scope reversible?** `calendar.readonly` costs you nothing if the token leaks, past exposure aside. A payment-initiation scope is not reversible once used. Weight your caution accordingly, the way connecting AI to your bank account already lays out for financial specifically: read-only visibility is a different risk class than an agent that can move money.
**Does the provider even offer a narrower scope?** Some APIs only offer coarse, all-or-nothing access. If the only option is "full account access," that is information: it tells you the integration is not ready for an agent yet, whatever the vendor's marketing says.
A permission audit you can run in ten minutes
Most people have never looked at what they have already granted. Fix that first, before adding anything new.
Google: myaccount.google.com/permissions lists every app and its exact scopes in plain language.
Microsoft: account.live.com/consent/Manage shows the same for Microsoft 365 and Outlook integrations.
GitHub: github.com/settings/installations and github.com/settings/applications list OAuth apps and GitHub App installations separately, worth checking both.
Revoke anything you do not recognize or no longer use. A scope granted to an experiment you abandoned six months ago is still live until you remove it.
What to look for in an agent platform's own consent screen
When an AI product asks you to connect an account, the consent screen itself tells you how seriously it takes this:
Signal | Narrow, well-designed | Broad, worth questioning |
|---|---|---|
Scope list | Specific: "read calendar events" | Vague: "access your Google account" |
Granularity | Separate toggles per capability | One all-or-nothing switch |
Default | Read-only until you opt into write | Write access granted upfront |
Revocation | In-app, one click | Only through the provider's own settings, buried |
If a product cannot tell you which specific scopes it is requesting, that is itself an answer.
The standing rule
Grant the narrowest scope that finishes the task in front of you today, not the scope that might save you a re-authorization next month. Re-authorizing is a thirty-second inconvenience. An agent with standing write access to your inbox, calendar, or accounts sitting unused for months is a liability with your name on it, waiting for the one prompt injection that finds it.
Frequently asked questions
What is the difference between OAuth scope and OAuth permission?
They are usually the same thing in practice. "Scope" is the technical term for the specific string a provider defines (like `drive.readonly`); "permission" is the plain-language description a consent screen shows you. Always check the underlying scope name when a provider will show it, since plain-language summaries sometimes undersell how broad a grant actually is.
Can I limit an AI agent's OAuth scope after I have already granted broad access?
Usually yes. Revoke the existing grant in the provider's account settings, then re-authorize with a narrower scope if the integration supports one. Some platforms force an all-or-nothing re-grant, which is itself useful information about how the integration was built.
Does a read-only scope mean an AI agent cannot leak my data?
No. Read-only prevents the agent from modifying or deleting anything, but it can still read sensitive data and include it in an output that gets logged, sent to a third party, or exposed through a prompt injection that tricks it into repeating what it read. Read-only reduces blast radius, it does not eliminate it.
Why would a company build a narrow, purpose-built integration instead of requesting broad access once?
Because broad access is a bigger target and a bigger liability if anything goes wrong, for the company as much as the user. A narrow integration also signals to security-conscious customers, and to enterprise buyers running vendor reviews, that the product was built with least-privilege access in mind rather than developer convenience.
The same pattern shows up in consumer subscriptions. With Sign in with ChatGPT, signing out of a partner app does not end its connection, so the grant has to be removed in settings.
How did this land?
About the author

Senior Editor, AI & Product
Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.


