read:tables |
Read table metadata, columns, and rows. |
The user can limit this to selected tables |
write:tables |
Modify rows, columns, and metadata of granted tables; create new tables (newly-created tables are auto-added to the grant). |
The user can limit this to selected tables |
read:boards |
Read board metadata, lanes, fields, cards, and comments. |
The user can limit this to selected boards |
write:boards |
Modify lanes, fields, cards, labels, comments, and metadata of granted boards; create new boards (newly-created boards are auto-added to the grant). |
The user can limit this to selected boards |
read:folders |
Read folder structure for granted folders. Does not cascade to tables inside the folder — apps need read:tables for those. |
The user can limit this to selected folders |
write:folders |
Manage granted folders. |
The user can limit this to selected folders |
read:search_histories |
Read granted saved searches. |
The user can limit this to selected saved searches |
write:search_histories |
Manage granted saved searches. |
The user can limit this to selected saved searches |
read:documents |
Read granted documents and their published history. |
The user can limit this to selected documents |
write:documents |
Create documents and edit, publish, or manage granted documents. |
The user can limit this to selected documents |
read:prospector |
Read Prospector runs and validate setup in granted team workspaces. A personal run has no workspace resource; App grants for personal runs are checked without a resource id. |
The user can limit this to selected workspaces |
write:prospector |
Manage Prospector run settings and results in granted team workspaces. A personal run has no workspace resource; App grants for personal runs are checked without a resource id. |
The user can limit this to selected workspaces |
execute:prospector |
Start or resume paid Prospector work in granted team workspaces. A personal run has no workspace resource; App grants for personal runs are checked without a resource id. |
The user can limit this to selected workspaces; Graph One must approve this for third-party apps |
read:workspaces |
Read granted workspaces. |
The user can limit this to selected workspaces |
write:workspaces |
Create team workspaces, manage roster, settings, slugs, outside shares, and delete empty workspaces. |
The user can limit this to selected workspaces |
read:workflows |
Read granted workflows and their published versions, excluding runs. |
The user can limit this to selected workflows |
write:workflows |
Create workflows; edit, publish and manage granted workflows. |
The user can limit this to selected workflows |
execute:workflows |
Start granted workflows using your own service access and credits. Workflow read access is still required. |
The user can limit this to selected workflows |
read:workflow-runs |
Read separately granted workflow runs and their accepted results. |
The user can limit this to selected workflow runs |
write:workflow-runs |
Control granted workflow runs. Resuming or retrying work uses your own service access and credits. |
The user can limit this to selected workflow runs |
read:facts |
Read current public org facts, sources, and supporting evidence. |
No extra picker or approval |
write:facts |
Submit and withdraw evidence flags on public facts, sources, and conflicts. Does not allow moderation. |
No extra picker or approval |
execute:facts |
Validate public sources and extract public org facts through workflow tasks. Does not allow moderation. |
Graph One must approve this for third-party apps |
read:profile |
Read your basic profile information (name, email, avatar). |
No extra picker or approval |
read:people |
Read person profiles in your graph. |
The user must choose at least one connected account; Graph One must approve this for third-party apps |
read:organisations |
Read organisation profiles in your reach. |
The user must choose at least one connected account |
read:team-people |
Read team-scoped people endpoints for the workspaces you grant access to. |
The user can limit this to selected workspaces; Graph One must approve this for third-party apps |
read:team-organisations |
Read team-scoped organisation endpoints for the workspaces you grant access to. |
The user can limit this to selected workspaces; Graph One must approve this for third-party apps |
read:connection-strength |
Read connection-strength data between you and others. |
The user must choose at least one connected account; Graph One must approve this for third-party apps |
write:connection-strength |
Override connection-strength values in your graph. |
The user must choose at least one connected account; Graph One must approve this for third-party apps |
read:feed |
Read your activity feed. |
No extra picker or approval |
read:sync |
Read sync state (which inboxes/calendars are connected and their last-synced timestamps) for the connected accounts you select. |
The user must choose at least one connected account |
offline_access |
Issue a long-lived refresh token so the app can keep accessing your data when you are not signed in. |
No extra picker or approval |
execute:search |
Run people and organisation search queries. |
No extra picker or approval |
execute:semantic-search |
Run AI-powered natural-language search queries (consumes LLM credits from your account). |
Graph One must approve this for third-party apps |
read:investors |
Look up investor profiles and portfolio data. |
No extra picker or approval |
read:podcasts |
Look up podcast feeds and known-people on episodes. |
No extra picker or approval |
write:linkedin.profiles |
Write LinkedIn profile observations into your graph. |
Graph One must approve this for third-party apps |
write:linkedin.positions |
Write LinkedIn role/position observations into your graph. |
Graph One must approve this for third-party apps |
write:linkedin.educations |
Write LinkedIn education observations into your graph. |
Graph One must approve this for third-party apps |
write:linkedin.connections |
Write LinkedIn 1st-degree connection observations into your graph. |
Graph One must approve this for third-party apps |
write:linkedin.messages |
Write LinkedIn message (DM) observations into your graph. |
Graph One must approve this for third-party apps |
write:linkedin.reachability |
Write LinkedIn 2nd/3rd-degree reachability observations into your graph. |
Graph One must approve this for third-party apps |
read:profile-notes |
Read private or team-shared notes and replies you may access. |
Graph One must approve this for third-party apps |
write:profile-notes |
Create and manage profile notes and their replies. |
Graph One must approve this for third-party apps |