Skip to documentation
Browse documentation

Scoped OAuth access

Restrict connectors below full account access.

View raw

OAuth supports a base access mode plus optional resource restrictions.

Scope Effect
mcp Discover, execute and read results within the account's existing access
mcp:read Discover and read results; cannot execute or spend credits
platform:amazon Restrict the base access mode to this platform
capability:amazon.products.search Restrict the base access mode to this capability

Use exactly one base mode. Space-separated platform restrictions form an allowlist; capability restrictions form another allowlist. When both exist, a request must satisfy both. Restrictions never add account privileges or reveal private capabilities. For example, mcp:read platform:amazon permits reading Amazon jobs but no execution.

The consent page can narrow a requested grant to one platform and/or read-only access. Token refresh preserves the resulting grant; it cannot broaden it. Legacy mcp grants retain their existing behavior until revoked or replaced. Result access includes other applications' jobs within the permitted account and resources. A tool profile or pinning URL controls presentation, not permissions.

Credit prices and plans: Upscrape pricing