Gmail App Permissions, Scope by Scope
Google's consent screen paraphrases. The scope string is the contract. Here is what each one actually permits.
The scopes, from least to most powerful
- 1gmail.labels — create, list and delete labels. Cannot read a single message. Harmless on its own and rarely requested alone.
- 2gmail.send — send mail as you, and nothing else. It cannot read your inbox. Newsletter and CRM tools often use only this.
- 3gmail.readonly — read every message, thread, attachment and label in the mailbox. It cannot change anything, which also means it cannot file, draft or reply.
- 4gmail.compose — create, update and delete drafts, and send them. Combined with readonly it is a common assistant pairing.
- 5gmail.settings.basic — read and write filters, forwarding, vacation settings, send-as aliases and signatures. It is also what Gmail requires to register a push notification watch on the mailbox.
- 6gmail.modify — everything above in one scope: read, label, draft, send, move to Trash. The one thing it cannot do is delete a message permanently while bypassing Trash.
- 7https://mail.google.com/ — full access, including permanent deletion beyond recovery. This is the one to think hard about. It is also the only scope that lets an app empty your Trash and Spam.
What that actually means
- •The consent screen's wording for gmail.modify and full access differs by a few words and one of them is irreversible
- •Scopes are all-or-nothing per mailbox — there is no way to grant access to one label, one sender or one date range
- •Google's include_granted_scopes behaviour means a later consent can quietly accumulate on top of an earlier one
- •Approving a scope on a work account may be blocked or silently allowed depending on your Workspace admin's settings, with no explanation shown to you
The exact scopes Clarity requests
- 1openid, email and profile — identity only. These are how Clarity knows which account you are and what address to show in the app.
- 2https://www.googleapis.com/auth/gmail.modify — reading message bodies and attachments to classify them, applying the 01–08 labels, and creating and updating drafts in your Drafts folder.
- 3https://www.googleapis.com/auth/gmail.settings.basic — reading your send-as aliases and signature so a draft goes out from the right address with the right sign-off, and registering the Gmail watch that tells Clarity new mail has arrived.
- 4https://www.googleapis.com/auth/calendar.readonly — requested on a separate, later consent screen, only if you connect Calendar for scheduling. Read-only: Clarity reads free/busy to propose times, and never writes to a calendar from this grant.
- 5Not requested: https://mail.google.com/, Drive, Contacts, Chat, or any scope on another Google product.
- ✓Five scopes total on the mailbox grant, each traceable to a visible feature
- ✓Permanent deletion is not in the granted scope, so no bug or misfire can reach it
- ✓Calendar is a second, separate consent — declining it costs you scheduling and nothing else
- ✓Signature and alias access is the narrow settings.basic scope, not the full-access one
Who asks this
Workspace admin
Needs the literal scope strings to add Clarity to the API access allowlist before staff can connect.
Consultant with a client mailbox
Wants to grant only what scheduling needs and can decline the calendar consent independently of the mailbox one.
Security-minded freelancer
Compares the consent screen wording against the scope reference and wants the two to match — they do.
Frequently asked questions
Why does an email assistant need write access at all?
Because filing and drafting are writes. Applying a label, creating a draft reply, and archiving a message all modify the mailbox. An assistant on gmail.readonly could tell you what it thinks about an email but could not act on it — which is most of the product.
Can Clarity permanently delete my email?
No. Permanent deletion that bypasses Trash requires the https://mail.google.com/ scope, which Clarity does not request. Under gmail.modify the furthest anything can go is Trash, where Gmail keeps it for 30 days.
Why does Clarity need gmail.settings.basic?
Two reasons. It reads your send-as aliases and signature so a draft is composed from the correct address, which matters if you send from more than one. And Gmail requires it to register the push notification watch that tells Clarity a new message arrived, rather than polling your mailbox on a timer.
Does connecting Gmail also connect my Google Calendar?
No. Calendar is a separate OAuth consent requesting calendar.readonly, shown only if you set up scheduling. If you never complete that screen, Clarity has no calendar access.
What happens if my Workspace admin restricts third-party apps?
The connect will fail, usually with a generic Google error rather than a clear explanation. Ask your admin to allow the Clarity Inbox OAuth client for the gmail.modify and gmail.settings.basic scopes in the Workspace API controls.
Reference: Google's Gmail API scope reference
Related guides
Is It Safe to Connect Gmail to a Third-Party App?
What Gmail access a third-party app really gets, which scope to refuse, and what Clarity requests.
How to Revoke an App's Access to Gmail
The real steps to remove Gmail and Outlook app access — and what revoking does not delete.
Outlook App Permissions Explained
Microsoft Graph mail permissions in plain English, and the ones Clarity requests.
What it costs you
Roughly 9.1 hours a week
Estimate2.8 hrs of that we could cover
The rest stays yours — it is not repeatable.
106 hrs
a year, if the low end of the range holds
137
threads went quiet and nothing told you
Last 90 days · your own mail · illustrative figures
Clarity Inbox
Get your free inbox report
An interactive report on your last 90 days: where your hours actually went, what is still waiting on you, and how much of your email could run itself. Free, delivered in minutes.
Get my free reportTakes 2 minutes · No credit card · Nothing is sent without you
.png?token=eyJraWQiOiJzdG9yYWdlLXVybC1zaWduaW5nLWtleV80NzQxMTM1Ny0yOWQ5LTRjYjctYTQ2ZS1iMWRhZTM5MGQxNjQiLCJhbGciOiJIUzI1NiJ9.eyJ1cmwiOiJXZWJzaXRlIEFzc2V0cy9jbGFyaXR5LWluYm94LWxvZ28tKGRhcmstaGlyZXMpLnBuZyIsImlhdCI6MTc3MDY2MjMyOSwiZXhwIjo0ODkyNzI2MzI5fQ.l97-jsT-3RFJHPguXJZtFfhnzBNV69xS0XwfvOXYci0)