Understanding OAuth Consent for Marketplace Apps
What is OAuth for Marketplace Apps?
OAuth is a security standard that enables third-party applications to securely request permission to access specific parts of your CRM account. When you install an app from the Marketplace, it uses an OAuth link to ask for your consent to read or modify data, such as contacts, calendars, or workflows.
Previously, authorizing an app happened without a clear view of the permissions being granted. Now, a new consent screen provides a detailed summary of the app and the specific permissions it is requesting before you approve the installation.
Key Benefits of the New OAuth Experience
The updated process offers greater transparency and security when connecting new apps to your CRM.
- See the app's name and branding before confirming the installation.
- View a complete list of the permissions (called scopes) the app is requesting.
- Read a clear description of what each permission allows the app to do.
- Receive explicit warnings for sensitive permissions, such as the ability to create or edit users.
- This enhanced experience works for both standard and white-labeled Marketplace installations.
How the Updated OAuth Flow Works
When you click an installation link from an app's integration page, you are taken to a redesigned confirmation screen. This screen presents all the information you need to make an informed decision, including the app's identity and a full breakdown of the access it requires. It functions similarly to permission prompts you may have seen on other platforms.
White-Labeled OAuth Page Experience
The improved OAuth consent screen is also available on white-labeled Marketplace URLs. You will receive the same clear permission breakdown and security warnings, ensuring a consistent and secure experience regardless of the domain used for the installation.
Understanding App Permissions and Warnings
OAuth scopes define the precise level of access an app is requesting. For example:
- Contacts: readonly: Allows the app to view your contact list.
- Conversations: write: Allows the app to send messages on your behalf.
If an app asks for a sensitive scope, such as one that allows it to modify user permissions, you will see a prominent warning. These alerts help you identify requests for deep access so you can proceed with caution.
Best Practices for Authorizing App Access
To keep your data secure, follow these guidelines when connecting third-party apps:
- Always review the requested permissions carefully before authorizing.
- Only install apps from developers and partners you trust.
- Avoid apps that ask for more access than is necessary for their function.
- Periodically review and remove access for apps you no longer use.
To manage your connected apps, navigate to Settings > Connected Apps within your CRM dashboard.
Frequently Asked Questions
What happens if I deny access on the OAuth screen?
The app will not be installed and no data will be shared with it.
What are OAuth scopes?
Scopes are specific permissions that define what data or actions an app is allowed to access within your account.
How can I tell if a permission is sensitive?
Sensitive scopes, like those that allow writing user data, will trigger a special warning on the consent screen.
Does this affect apps I have already installed?
No. This new screen only appears when installing a new app or re-authorizing an existing one.
Can I use this for my private app?
Yes, private apps that use OAuth will also display the new permission details screen.