Blog/ Gmail how-tos

How to See Which Apps Have Access to Your Gmail

Nafiul HasanNafiul Hasan· 11 min read
Diagram of a Gmail account connected to several third-party apps by permission lines, illustrating a Google account app-access audit

The short answer

Go to myaccount.google.com/permissions in any browser — every third-party app with OAuth access to your Gmail appears there, along with what it is permitted to do. Click any app to read its scopes, flag anything over-privileged or unused, and remove access with one click. The whole review takes under ten minutes.

How to see which apps have access to your Gmail — what the OAuth scopes really permit, which grants deserve immediate removal, and a review checklist.

On this page
  1. 01What do Gmail app permission scopes actually allow?
  2. 02How do I check which apps have access to my Gmail?
  3. 03How does the view differ across platforms?
  4. 04What to do when the list does not show what you expect
  5. 05A faster way: keeping access review continuous

The fastest way to see what apps have access to your Gmail is to open myaccount.google.com/permissions. Every third-party tool that asked you to sign in with Google or requested Gmail access appears there, along with exactly what it is permitted to do. Most people approve these during a signup flow, forget they exist, and never look again — leaving years of granted access accumulating quietly in the background.

That accumulation is worth reviewing. A productivity app you used once still holds the permissions you granted on day one. A service that has since been acquired, changed its privacy terms, or shut down its servers may still hold a live credential against your inbox. The permissions page reveals all of it in one place, and the review takes under ten minutes once you know what you are looking at. This guide walks you through each step, explains what the permission labels actually mean, and shows you which grants deserve immediate removal.

What do Gmail app permission scopes actually allow?#

Most people click through the Google permission dialog without reading it carefully, which means they have granted access they cannot fully describe. Understanding what the key scopes actually permit is the most important part of any review, because how urgently you should act on a grant depends entirely on which category it falls into.

When Google displays permissions in plain English inside the permissions page, the wording is written for ordinary users rather than developers. The scope that shows as 'Read, compose, send, and permanently delete all your email' is the broadest permission available and maps to the mail.google.com OAuth scope — sometimes described in authorization dialogs as 'Have offline access' or 'Manage your email.' The exact phrasing varies by app and by how the developer registered the permission request. The table below maps the labels you will encounter to what each scope actually allows.

One thing the permissions page does not surface: these scopes cover only apps that connected via OAuth, the standard 'sign in with Google' handshake. Apps that authenticate with a Google App Password — a direct login credential, used by many email clients — do not appear here at all. Section five explains how to find those.

Scope (as shown in OAuth flow)What the app can doRisk level
mail.google.com — Read, compose, send, and permanently delete all your emailFull mailbox read and write, send in your name, permanently delete messages — no further confirmation requiredHighest — functionally equivalent to sharing your password
gmail.modify — All mail access except permanent deletionRead all messages, compose and send email, move messages, apply or remove labelsHigh — full read and send access
gmail.readonly — View your email messages and settingsRead every message, thread, and account setting — cannot send, delete, or modify anythingModerate — can see everything, cannot act
gmail.send — Send email on your behalfSend messages in your name only — cannot read any of your existing mailModerate — cannot read your mail
gmail.compose — Manage drafts and send emailsCreate and send drafts; limited read of draft content onlyLow to moderate — cannot read received mail
gmail.metadata — View email message metadata onlyRead message headers, labels, and thread IDs — cannot see message bodies or attachmentsLow — cannot read email content

The mail.google.com scope is equivalent to sharing your password

An app that holds the mail.google.com scope can read every message in your account, compose and send email in your name, and permanently delete mail — with no further action from you. This access does not expire on its own. Any app you are no longer actively using that holds this scope should be removed immediately.

How do I check which apps have access to my Gmail?#

  1. 1

    Open myaccount.google.com/permissions

    Type that URL directly into any browser — you do not need to be in Gmail first. If you are signed into more than one Google account, check which account is active in the top-right corner before you start. The permissions list is account-specific, and it is easy to audit the wrong one without noticing.

  2. 2

    Scroll through the full list

    Every third-party app with active OAuth access appears here. The list shows a brief description for each app and the date the access was last granted. Scroll all the way to the bottom rather than stopping at the first few entries — apps you connected years ago appear further down, and those are often the most over-privileged.

  3. 3

    Click each app to read its scopes

    The summary shown in the list is brief. Click the app name to expand its detail view, which shows the specific permissions it holds in plain English. Cross-reference against the scope table in the previous section to assess whether the access level is proportionate to what the app actually does for you.

  4. 4

    Flag apps in three categories

    First: apps you no longer use or do not recognise. Second: apps holding broader access than their function warrants — a summarization tool that holds send access is a common example. Third: apps that were useful once but have since been acquired by a company you do not know. Any of the three is a reason to remove the grant.

  5. 5

    Remove access for each flagged app

    Click 'Remove Access' on any app you want to disconnect. Revocation is immediate — the app loses all live access to your Gmail the moment you confirm. If you ever want to reconnect it, the app will prompt you to re-authorize. Revoking access does not delete data the app already downloaded before revocation; it only closes the live credential going forward.

  6. 6

    Set a recurring reminder

    Connected apps accumulate faster than most people expect. Apps from startup tools, one-off automation experiments, or conference demos can all leave OAuth grants behind. A quarterly review — every three to six months — takes under ten minutes once you have done it once and is the single most reliable habit for keeping this list clean.

How does the view differ across platforms?#

The permissions page at myaccount.google.com/permissions works in any browser on any platform, and it is always the most complete view — it shows the full scope detail and lets you remove access in one click. The paths below show how to reach the equivalent on a phone or from a managed work account.

For Google Workspace accounts, there are two separate layers of control. The permissions page shows only the apps you have personally authorized via OAuth. Your administrator manages a parallel set of organization-approved apps from the admin console, and those grants are not visible on the end-user permissions page. If your organization has restricted third-party app access, you may find that new OAuth connection requests are blocked before they reach you, or that the permissions page shows fewer apps than you expected.

PlatformHow to reach the connected-apps viewWhat to know
Web browser (any device)Go to myaccount.google.com/permissions directlyMost complete view; shows all scope detail and lets you remove access immediately
AndroidOpen Settings, tap your Google account, tap Security, scroll to Third-party apps with account accessShows the same apps as the web view; scope detail may be summarized — use the web path to read exact permissions
iPhone or iPadOpen Safari or any browser and go to myaccount.google.com/permissions — no dedicated iOS Google Account app shows thisThe Gmail iOS app does not surface connected-app permissions; the browser path is the only option on iOS
Google Workspace (work account)myaccount.google.com/permissions shows your personal OAuth grants; org-wide app management is in the admin consoleAdmins can revoke access organization-wide from the admin console — you may see fewer apps if admin policy restricts what can connect

What to do when the list does not show what you expect#

Two situations come up regularly during a permissions audit. The first is finding an app you cannot account for. The second is expecting to see an app that you know uses your Gmail but cannot find on the page.

A missing app almost always means the tool authenticates via IMAP or SMTP rather than OAuth. Email clients are the most common example — they often connect using a Google App Password, which is a direct login credential generated for a specific app. These credentials do not appear on the permissions page. To find them, go to myaccount.google.com/apppasswords. Any app password listed there has credential-level access to your account for the email protocols it was generated for. Revoke any you do not recognise or have not actively used.

An unrecognised app in the OAuth list warrants a different response. Before removing it, check three things: the app name in the permissions list is often the developer's internal product name rather than the brand you recognize, so a CRM or scheduling tool may appear under an unfamiliar identifier; the date the access was granted may help you place it in context; and some platforms — automation tools, business apps — authenticate on your behalf under their own developer name rather than the service name you use day to day. If none of those apply and the app remains unaccountable, remove the access and watch to see which connected service stops working.

An app you never authorized is a security incident

If you find an OAuth grant you cannot explain and are confident you never approved, treat it as a compromised account. Change your Google Account password immediately, enable two-step verification if it is not already active, and review recent account activity at myaccount.google.com/device-activity. A connected app you never authorized can indicate a phishing login that generated an OAuth grant rather than stealing your password — and OAuth grants do not expire on their own.

A faster way: keeping access review continuous#

The manual audit above is a point-in-time snapshot — you review, you clean up, and the list starts accumulating again. The harder problem is that an app holding broad Gmail access, granted months ago, can continue reading your mail without any visible event in your inbox. There is no notification when an old OAuth grant is exercised.

AI Emaily's spam protection layer surfaces signals from senders that exhibit patterns consistent with unwanted bulk or automated access — giving you an in-inbox indicator alongside your actual mail rather than requiring a separate security dashboard. Because AI Emaily connects to your Gmail via OAuth itself, the permission it requests is visible in the same permissions page you just reviewed: it asks for the minimum access its features require, not blanket account control. We build AI Emaily. If you want a mail client that surfaces these signals in the flow of your inbox rather than a separate audit tab, it is worth a look.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Keep your Gmail access under control

AI Emaily connects to Gmail with the minimum permissions it needs — visible in the same permissions page you just reviewed — and surfaces spam and unwanted bulk-access signals in your inbox rather than in a separate dashboard. Start free at app.aiemaily.com/signup.

  • 7-day free trial
  • Cancel anytime
  • Every provider