domainwidedelegation.comStart free

Use cases → Admin and governance

Report application access across the entire organisation

Survey which third-party and internal apps have OAuth access in your Workspace tenant using a service account with domain-wide delegation.

Who it is forIT security teams and Workspace administrators responsible for monitoring external app access.
APIsAdmin SDK
Typical scopesadmin.reports.audit.readonly, admin.directory.user.readonly

The problem

Untracked app authorisations create security gaps and compliance risks. Manual spot-checking misses users and does not scale, leaving dormant or malicious apps undetected.

How it works

  1. Use a service account with domain-wide delegation to impersonate users.
  2. List all users in the domain via the Directory API.
  3. Iterate over users and fetch each user's authorised OAuth clients using the Tokens API.
  4. Aggregate and report which apps have access and which scopes they hold.

What changes

You see a current record of all app authorisations in the domain, with enough detail to audit or remediate risky access.

The trap in this one. The Tokens API only lists authorisations per user, and users who have never authorised an app are omitted entirely — there is no explicit 'no apps' record. Bulk queries can silently skip suspended users or those with mailbox-only licences, so totals can be off unless you cross-check against the user list. If you query too quickly, Admin SDK rate limits return 429s without Retry-After headers, requiring explicit backoff logic.

Questions people ask

Can I see which scopes each app has for a user?

Yes, the Tokens API returns the list of scopes granted to each OAuth client per user. Parse these carefully, as scope strings are case-sensitive and not always documented.

How often should I run the report?

Daily or weekly is typical. Note that revocations or new grants can appear with a delay of several hours in the API.

Want this built?

This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.

Talk to us Or read the setup guide

Related use cases

Audit which third-party apps can read your mail

List every OAuth grant across the domain and find the retired tools still holding access.

Automate joiners, movers and leavers

Create accounts, set group membership, provision Drive and hand over mailboxes without a manual checklist.

Continuously verify your delegation still works

A scheduled probe that proves every API still answers under every tenant, before a customer finds out otherwise.