Clarity Inbox
Trust

Gmail App Permissions, Scope by Scope

Google's consent screen paraphrases. The scope string is the contract. Here is what each one actually permits.

Read summarized version withChatGPTChatGPTPerplexityPerplexityGeminiGeminiClaudeClaudeGrokGrok

The scopes, from least to most powerful

  1. 1gmail.labels — create, list and delete labels. Cannot read a single message. Harmless on its own and rarely requested alone.
  2. 2gmail.send — send mail as you, and nothing else. It cannot read your inbox. Newsletter and CRM tools often use only this.
  3. 3gmail.readonly — read every message, thread, attachment and label in the mailbox. It cannot change anything, which also means it cannot file, draft or reply.
  4. 4gmail.compose — create, update and delete drafts, and send them. Combined with readonly it is a common assistant pairing.
  5. 5gmail.settings.basic — read and write filters, forwarding, vacation settings, send-as aliases and signatures. It is also what Gmail requires to register a push notification watch on the mailbox.
  6. 6gmail.modify — everything above in one scope: read, label, draft, send, move to Trash. The one thing it cannot do is delete a message permanently while bypassing Trash.
  7. 7https://mail.google.com/ — full access, including permanent deletion beyond recovery. This is the one to think hard about. It is also the only scope that lets an app empty your Trash and Spam.

What that actually means

  • The consent screen's wording for gmail.modify and full access differs by a few words and one of them is irreversible
  • Scopes are all-or-nothing per mailbox — there is no way to grant access to one label, one sender or one date range
  • Google's include_granted_scopes behaviour means a later consent can quietly accumulate on top of an earlier one
  • Approving a scope on a work account may be blocked or silently allowed depending on your Workspace admin's settings, with no explanation shown to you

The exact scopes Clarity requests

  1. 1openid, email and profile — identity only. These are how Clarity knows which account you are and what address to show in the app.
  2. 2https://www.googleapis.com/auth/gmail.modify — reading message bodies and attachments to classify them, applying the 01–08 labels, and creating and updating drafts in your Drafts folder.
  3. 3https://www.googleapis.com/auth/gmail.settings.basic — reading your send-as aliases and signature so a draft goes out from the right address with the right sign-off, and registering the Gmail watch that tells Clarity new mail has arrived.
  4. 4https://www.googleapis.com/auth/calendar.readonly — requested on a separate, later consent screen, only if you connect Calendar for scheduling. Read-only: Clarity reads free/busy to propose times, and never writes to a calendar from this grant.
  5. 5Not requested: https://mail.google.com/, Drive, Contacts, Chat, or any scope on another Google product.
  • Five scopes total on the mailbox grant, each traceable to a visible feature
  • Permanent deletion is not in the granted scope, so no bug or misfire can reach it
  • Calendar is a second, separate consent — declining it costs you scheduling and nothing else
  • Signature and alias access is the narrow settings.basic scope, not the full-access one

Who asks this

Workspace admin

Needs the literal scope strings to add Clarity to the API access allowlist before staff can connect.

Consultant with a client mailbox

Wants to grant only what scheduling needs and can decline the calendar consent independently of the mailbox one.

Security-minded freelancer

Compares the consent screen wording against the scope reference and wants the two to match — they do.

Frequently asked questions

Why does an email assistant need write access at all?

Because filing and drafting are writes. Applying a label, creating a draft reply, and archiving a message all modify the mailbox. An assistant on gmail.readonly could tell you what it thinks about an email but could not act on it — which is most of the product.

Can Clarity permanently delete my email?

No. Permanent deletion that bypasses Trash requires the https://mail.google.com/ scope, which Clarity does not request. Under gmail.modify the furthest anything can go is Trash, where Gmail keeps it for 30 days.

Why does Clarity need gmail.settings.basic?

Two reasons. It reads your send-as aliases and signature so a draft is composed from the correct address, which matters if you send from more than one. And Gmail requires it to register the push notification watch that tells Clarity a new message arrived, rather than polling your mailbox on a timer.

Does connecting Gmail also connect my Google Calendar?

No. Calendar is a separate OAuth consent requesting calendar.readonly, shown only if you set up scheduling. If you never complete that screen, Clarity has no calendar access.

What happens if my Workspace admin restricts third-party apps?

The connect will fail, usually with a generic Google error rather than a clear explanation. Ask your admin to allow the Clarity Inbox OAuth client for the gmail.modify and gmail.settings.basic scopes in the Workspace API controls.

Reference: Google's Gmail API scope reference

Related guides

What it costs you

Roughly 9.1 hours a week

Estimate
Writing replies
6.4
Reading & triage
1.1
Follow-up tracking
0.9
Chasing & state
0.7

2.8 hrs of that we could cover

The rest stays yours — it is not repeatable.

106 hrs

a year, if the low end of the range holds

137

threads went quiet and nothing told you

Last 90 days · your own mail · illustrative figures

Clarity Inbox

Get your free inbox report

An interactive report on your last 90 days: where your hours actually went, what is still waiting on you, and how much of your email could run itself. Free, delivered in minutes.

Get my free report

Takes 2 minutes · No credit card · Nothing is sent without you