Microsoft Outlook · OAuth Scopes

Microsoft Outlook OAuth Scopes

OAuth 2.0 searched

Microsoft Outlook publishes 20 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Microsoft Outlook API on a user’s behalf.

Tokens are issued from https://login.microsoftonline.com/common/oauth2/v2.0/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CalendarContactsEmailEnterpriseMicrosoftOffice 365Productivity
Scopes: 20 Flows: authorizationCode Method: searched

OAuth endpoints

Authorization URL
https://login.microsoftonline.com/common/oauth2/v2.0/authorize
Token URL
https://login.microsoftonline.com/common/oauth2/v2.0/token
Flows
authorizationCode

Scopes (20)

ScopeDescriptionFlows
Mail.Read Read user mail authorizationCode
Mail.ReadBasic Read user basic mail (no body/attachments) authorizationCode
Mail.Read.Shared Read mail in shared mailboxes authorizationCode
Mail.ReadWrite Read and write access to user mail authorizationCode
Mail.ReadWrite.Shared Read and write mail in shared mailboxes authorizationCode
Mail.Send Send mail as a user authorizationCode
Mail.Send.Shared Send mail on behalf of others authorizationCode
MailboxSettings.Read Read user mailbox settings (automatic replies authorizationCode
MailboxSettings.ReadWrite Read and write user mailbox settings authorizationCode
MailboxFolder.Read Read user mail folders authorizationCode
MailboxFolder.ReadWrite Read and write user mail folders authorizationCode
Calendars.Read Read user calendars authorizationCode
Calendars.ReadWrite Read and write user calendars authorizationCode
Contacts.Read Read user contacts authorizationCode
Contacts.ReadWrite Read and write user contacts authorizationCode
Tasks.Read Read user tasks and to-do lists authorizationCode
Tasks.ReadWrite Create authorizationCode
People.Read Read the signed-in user's relevant people list authorizationCode
User.Read Sign in and read the user's profile authorizationCode
offline_access Maintain access via refresh tokens authorizationCode

Source

OAuth Scopes

Raw ↑
generated: '2026-06-20'
method: searched
source: openapi/microsoft-graph-mail-api-openapi.yml
docs: https://learn.microsoft.com/en-us/graph/permissions-reference
note: >-
  Microsoft identity platform (Entra ID) OAuth 2.0 permissions. Scopes exist in
  delegated (user-consented) and application (app-only) forms; the strings below
  are the delegated names. The OpenAPI declares only the mail subset — the wider
  Outlook surface (calendar, contacts, tasks, mailbox settings) is enriched from
  the Microsoft Graph permissions reference.
schemes:
  - name: oauth2
    source: openapi/microsoft-graph-mail-api-openapi.yml
    flows:
      - flow: authorizationCode
        authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize
        tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token
    description: Microsoft identity platform OAuth 2.0 authorization. Supports delegated (user) and application permissions.
scopes:
  - {scope: Mail.Read, description: Read user mail, flows: [authorizationCode], sources: [openapi/microsoft-graph-mail-api-openapi.yml]}
  - {scope: Mail.ReadBasic, description: Read user basic mail (no body/attachments), flows: [authorizationCode], sources: [openapi/microsoft-graph-mail-api-openapi.yml]}
  - {scope: Mail.Read.Shared, description: Read mail in shared mailboxes, flows: [authorizationCode], sources: [openapi/microsoft-graph-mail-api-openapi.yml]}
  - {scope: Mail.ReadWrite, description: Read and write access to user mail, flows: [authorizationCode], sources: [openapi/microsoft-graph-mail-api-openapi.yml]}
  - {scope: Mail.ReadWrite.Shared, description: Read and write mail in shared mailboxes, flows: [authorizationCode], sources: [openapi/microsoft-graph-mail-api-openapi.yml]}
  - {scope: Mail.Send, description: Send mail as a user, flows: [authorizationCode], sources: [openapi/microsoft-graph-mail-api-openapi.yml]}
  - {scope: Mail.Send.Shared, description: Send mail on behalf of others, flows: [authorizationCode], sources: [docs]}
  - {scope: MailboxSettings.Read, description: Read user mailbox settings (automatic replies, time zone, language), flows: [authorizationCode], sources: [docs]}
  - {scope: MailboxSettings.ReadWrite, description: Read and write user mailbox settings, flows: [authorizationCode], sources: [docs]}
  - {scope: MailboxFolder.Read, description: Read user mail folders, flows: [authorizationCode], sources: [docs]}
  - {scope: MailboxFolder.ReadWrite, description: Read and write user mail folders, flows: [authorizationCode], sources: [docs]}
  - {scope: Calendars.Read, description: Read user calendars, flows: [authorizationCode], sources: [docs]}
  - {scope: Calendars.ReadWrite, description: Read and write user calendars, flows: [authorizationCode], sources: [docs]}
  - {scope: Contacts.Read, description: Read user contacts, flows: [authorizationCode], sources: [docs]}
  - {scope: Contacts.ReadWrite, description: Read and write user contacts, flows: [authorizationCode], sources: [docs]}
  - {scope: Tasks.Read, description: Read user tasks and to-do lists, flows: [authorizationCode], sources: [docs]}
  - {scope: Tasks.ReadWrite, description: Create, read, update, delete user tasks and to-do lists, flows: [authorizationCode], sources: [docs]}
  - {scope: People.Read, description: Read the signed-in user's relevant people list, flows: [authorizationCode], sources: [docs]}
  - {scope: User.Read, description: Sign in and read the user's profile, flows: [authorizationCode], sources: [docs]}
  - {scope: offline_access, description: Maintain access via refresh tokens, flows: [authorizationCode], sources: [docs]}