Scoped OAuth access
Restrict connectors below full account access.
OAuth supports a base access mode plus optional resource restrictions.
| Scope | Effect |
|---|---|
mcp |
Discover, execute and read results within the account's existing access |
mcp:read |
Discover and read results; cannot execute or spend credits |
platform:amazon |
Restrict the base access mode to this platform |
capability:amazon.products.search |
Restrict the base access mode to this capability |
Use exactly one base mode. Space-separated platform restrictions form an allowlist;
capability restrictions form another allowlist. When both exist, a request must
satisfy both. Restrictions never add account privileges or reveal private capabilities.
For example, mcp:read platform:amazon permits reading Amazon jobs but no execution.
The consent page can narrow a requested grant to one platform and/or read-only
access. Token refresh preserves the resulting grant; it cannot broaden it.
Legacy mcp grants retain their existing behavior until revoked or replaced.
Result access includes other applications' jobs within the permitted account and
resources. A tool profile or pinning URL controls presentation, not permissions.
Credit prices and plans: Upscrape pricing