How to See Which Apps Have Access to Your Gmail

The short answer
Go to myaccount.google.com/permissions in any browser — every third-party app with OAuth access to your Gmail appears there, along with what it is permitted to do. Click any app to read its scopes, flag anything over-privileged or unused, and remove access with one click. The whole review takes under ten minutes.
How to see which apps have access to your Gmail — what the OAuth scopes really permit, which grants deserve immediate removal, and a review checklist.
On this page
The fastest way to see what apps have access to your Gmail is to open myaccount.google.com/permissions. Every third-party tool that asked you to sign in with Google or requested Gmail access appears there, along with exactly what it is permitted to do. Most people approve these during a signup flow, forget they exist, and never look again — leaving years of granted access accumulating quietly in the background.
That accumulation is worth reviewing. A productivity app you used once still holds the permissions you granted on day one. A service that has since been acquired, changed its privacy terms, or shut down its servers may still hold a live credential against your inbox. The permissions page reveals all of it in one place, and the review takes under ten minutes once you know what you are looking at. This guide walks you through each step, explains what the permission labels actually mean, and shows you which grants deserve immediate removal.
What do Gmail app permission scopes actually allow?#
Most people click through the Google permission dialog without reading it carefully, which means they have granted access they cannot fully describe. Understanding what the key scopes actually permit is the most important part of any review, because how urgently you should act on a grant depends entirely on which category it falls into.
When Google displays permissions in plain English inside the permissions page, the wording is written for ordinary users rather than developers. The scope that shows as 'Read, compose, send, and permanently delete all your email' is the broadest permission available and maps to the mail.google.com OAuth scope — sometimes described in authorization dialogs as 'Have offline access' or 'Manage your email.' The exact phrasing varies by app and by how the developer registered the permission request. The table below maps the labels you will encounter to what each scope actually allows.
One thing the permissions page does not surface: these scopes cover only apps that connected via OAuth, the standard 'sign in with Google' handshake. Apps that authenticate with a Google App Password — a direct login credential, used by many email clients — do not appear here at all. Section five explains how to find those.
| Scope (as shown in OAuth flow) | What the app can do | Risk level |
|---|---|---|
| mail.google.com — Read, compose, send, and permanently delete all your email | Full mailbox read and write, send in your name, permanently delete messages — no further confirmation required | Highest — functionally equivalent to sharing your password |
| gmail.modify — All mail access except permanent deletion | Read all messages, compose and send email, move messages, apply or remove labels | High — full read and send access |
| gmail.readonly — View your email messages and settings | Read every message, thread, and account setting — cannot send, delete, or modify anything | Moderate — can see everything, cannot act |
| gmail.send — Send email on your behalf | Send messages in your name only — cannot read any of your existing mail | Moderate — cannot read your mail |
| gmail.compose — Manage drafts and send emails | Create and send drafts; limited read of draft content only | Low to moderate — cannot read received mail |
| gmail.metadata — View email message metadata only | Read message headers, labels, and thread IDs — cannot see message bodies or attachments | Low — cannot read email content |
The mail.google.com scope is equivalent to sharing your password
How do I check which apps have access to my Gmail?#
- 1
Open myaccount.google.com/permissions
Type that URL directly into any browser — you do not need to be in Gmail first. If you are signed into more than one Google account, check which account is active in the top-right corner before you start. The permissions list is account-specific, and it is easy to audit the wrong one without noticing.
- 2
Scroll through the full list
Every third-party app with active OAuth access appears here. The list shows a brief description for each app and the date the access was last granted. Scroll all the way to the bottom rather than stopping at the first few entries — apps you connected years ago appear further down, and those are often the most over-privileged.
- 3
Click each app to read its scopes
The summary shown in the list is brief. Click the app name to expand its detail view, which shows the specific permissions it holds in plain English. Cross-reference against the scope table in the previous section to assess whether the access level is proportionate to what the app actually does for you.
- 4
Flag apps in three categories
First: apps you no longer use or do not recognise. Second: apps holding broader access than their function warrants — a summarization tool that holds send access is a common example. Third: apps that were useful once but have since been acquired by a company you do not know. Any of the three is a reason to remove the grant.
- 5
Remove access for each flagged app
Click 'Remove Access' on any app you want to disconnect. Revocation is immediate — the app loses all live access to your Gmail the moment you confirm. If you ever want to reconnect it, the app will prompt you to re-authorize. Revoking access does not delete data the app already downloaded before revocation; it only closes the live credential going forward.
- 6
Set a recurring reminder
Connected apps accumulate faster than most people expect. Apps from startup tools, one-off automation experiments, or conference demos can all leave OAuth grants behind. A quarterly review — every three to six months — takes under ten minutes once you have done it once and is the single most reliable habit for keeping this list clean.
How does the view differ across platforms?#
The permissions page at myaccount.google.com/permissions works in any browser on any platform, and it is always the most complete view — it shows the full scope detail and lets you remove access in one click. The paths below show how to reach the equivalent on a phone or from a managed work account.
For Google Workspace accounts, there are two separate layers of control. The permissions page shows only the apps you have personally authorized via OAuth. Your administrator manages a parallel set of organization-approved apps from the admin console, and those grants are not visible on the end-user permissions page. If your organization has restricted third-party app access, you may find that new OAuth connection requests are blocked before they reach you, or that the permissions page shows fewer apps than you expected.
| Platform | How to reach the connected-apps view | What to know |
|---|---|---|
| Web browser (any device) | Go to myaccount.google.com/permissions directly | Most complete view; shows all scope detail and lets you remove access immediately |
| Android | Open Settings, tap your Google account, tap Security, scroll to Third-party apps with account access | Shows the same apps as the web view; scope detail may be summarized — use the web path to read exact permissions |
| iPhone or iPad | Open Safari or any browser and go to myaccount.google.com/permissions — no dedicated iOS Google Account app shows this | The Gmail iOS app does not surface connected-app permissions; the browser path is the only option on iOS |
| Google Workspace (work account) | myaccount.google.com/permissions shows your personal OAuth grants; org-wide app management is in the admin console | Admins can revoke access organization-wide from the admin console — you may see fewer apps if admin policy restricts what can connect |
What to do when the list does not show what you expect#
Two situations come up regularly during a permissions audit. The first is finding an app you cannot account for. The second is expecting to see an app that you know uses your Gmail but cannot find on the page.
A missing app almost always means the tool authenticates via IMAP or SMTP rather than OAuth. Email clients are the most common example — they often connect using a Google App Password, which is a direct login credential generated for a specific app. These credentials do not appear on the permissions page. To find them, go to myaccount.google.com/apppasswords. Any app password listed there has credential-level access to your account for the email protocols it was generated for. Revoke any you do not recognise or have not actively used.
An unrecognised app in the OAuth list warrants a different response. Before removing it, check three things: the app name in the permissions list is often the developer's internal product name rather than the brand you recognize, so a CRM or scheduling tool may appear under an unfamiliar identifier; the date the access was granted may help you place it in context; and some platforms — automation tools, business apps — authenticate on your behalf under their own developer name rather than the service name you use day to day. If none of those apply and the app remains unaccountable, remove the access and watch to see which connected service stops working.
An app you never authorized is a security incident
A faster way: keeping access review continuous#
The manual audit above is a point-in-time snapshot — you review, you clean up, and the list starts accumulating again. The harder problem is that an app holding broad Gmail access, granted months ago, can continue reading your mail without any visible event in your inbox. There is no notification when an old OAuth grant is exercised.
AI Emaily's spam protection layer surfaces signals from senders that exhibit patterns consistent with unwanted bulk or automated access — giving you an in-inbox indicator alongside your actual mail rather than requiring a separate security dashboard. Because AI Emaily connects to your Gmail via OAuth itself, the permission it requests is visible in the same permissions page you just reviewed: it asks for the minimum access its features require, not blanket account control. We build AI Emaily. If you want a mail client that surfaces these signals in the flow of your inbox rather than a separate audit tab, it is worth a look.
Frequently asked
See it in AI Emaily
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.