Documentation menu

Scopes & permissions

A scope is the unit of consent you grant on the OAuth consent screen when connecting an assistant. Every tool call a connected assistant makes is checked against the scopes baked into its access token — not against a fresh read of your account role — so what you approve at connect time is exactly what stays approved until you revoke it or reconnect with a different selection.

The full list

ScopeWhat it allowsGranted by default?
projects:readSee your email projects and their designsYes
projects:writeCreate and edit email projectsYes
contacts:readSee your contact lists — summaries always; individual contact rows only when a tool explicitly asks for themYes
contacts:writeAdd and update contacts, manage unsubscribesYes
analytics:readSee campaign results, form responses and ordersYes
campaigns:readSee send history and recurring schedulesYes
campaigns:sendSend campaigns to your contacts, and create/enable recurring schedulesNo — opt-in only
templates:readUse your saved and community templatesYes
templates:writeSave a project as a templateYes
mailbox:readRead mail received at your verified domain, and support ticketsYes
mailbox:writeReply to mailbox threads and support ticketsYes
commerce:writeMark a physical product order fulfilledYes
journeys:readSee your automated journeys and saved segmentsYes
journeys:writeBuild journeys (always saved turned off), create segments, and pause journeys. Turning a journey on also needs campaigns:sendYes
openidConfirm your identityYes
emailShare your account email address (used for workspace domain restrictions on platforms that support them)Yes
offline_accessStay connected without re-authorizing every hourYes

Why campaigns:send is different

Every other scope here is either read-only or an edit you can undo (delete the block, remove the contact, restore the template). Sending mail to real people is the one action a connector can take that can't be taken back. That's why the consent screen leaves it unchecked by default, shows it with a distinct warning color, and — even once granted — still requires the two-step prepare_send/confirm_send flow described in Security before anything actually goes out.

How your account role limits scopes

If you're a viewer on the account you're connecting as, the consent screen only offers *:read scopes plus openid/email/offline_access — the same read-only ceiling a viewer already has everywhere else in MailInApp. Editors and owners can grant the full list; the one thing neither can grant is anything a connector doesn't expose at all — credential rotation, SMTP/payments/domain settings, and team management stay unreachable from any connector tool, regardless of scope, mirroring the existing editor carve-outs elsewhere in the product.

Which account a connection acts as

A connection is scoped to one account for its whole lifetime. If you belong to more than one company — your own personal account, plus any team you're an active member of — the consent screen asks you to pick one before showing you scopes. Working across two companies from the same assistant means connecting twice, which also gives you two independently revocable entries on the Connections page.

That account binding is re-checked on every single tool call, not just at connect time: if a team owner removes you as a teammate, or your role changes, the next call from that connection reflects your current standing — never the standing you had when you granted the scopes.