Microsoft Word · OAuth Scopes

Microsoft Word OAuth Scopes

OAuth 2.0 searched

Microsoft Word publishes 8 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Microsoft Word API on a user’s behalf.

Tokens are issued from https://login.microsoftonline.com/common/oauth2/v2.0/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

DocumentsMicrosoft 365OfficeProductivityWord Processing
Scopes: 8 Flows: authorizationCode Method: searched

OAuth endpoints

Authorization URL
https://login.microsoftonline.com/common/oauth2/v2.0/authorize
Token URL
https://login.microsoftonline.com/common/oauth2/v2.0/token
Flows
authorizationCode

Scopes (8)

ScopeDescriptionFlows
Files.Read Read the signed-in user's files. authorizationCode
Files.Read.All Read all files the signed-in user can access. authorizationCode
Files.ReadWrite Read and write the signed-in user's files. authorizationCode
Files.ReadWrite.All Read and write all files the signed-in user can access. authorizationCode
Files.ReadWrite.AppFolder Read and write files in the application's dedicated folder. authorizationCode
Sites.Read.All Read items in all SharePoint site collections the user can access (SharePoint document libraries). authorizationCode
Sites.ReadWrite.All Read and write items in all SharePoint site collections (admin consent typically required). authorizationCode
User.Read Sign in and read the signed-in user's profile (baseline scope requested at login). authorizationCode

Source

OAuth Scopes

Raw ↑
generated: '2026-06-20'
method: searched
source: openapi/microsoft-word-graph-api.yaml, openapi/microsoft-word-javascript-api.yaml
docs: https://learn.microsoft.com/en-us/graph/permissions-reference
notes: >-
  Microsoft Graph permissions (scopes) for the Word document surface are the Files.*
  and Sites.* permission families. Each exists as a delegated and an application
  permission; .All variants and Sites.* permissions typically require admin consent.
  Scopes below extend the four declared in the OpenAPI with the additional documented
  file/site permissions that Word-in-OneDrive/SharePoint operations use.
schemes:
- name: oauth2
  source: openapi/microsoft-word-graph-api.yaml
  flows:
  - flow: authorizationCode
    authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize
    tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token
  description: OAuth 2.0 authorization code flow with Microsoft Identity Platform.
- name: oauth2
  source: openapi/microsoft-word-javascript-api.yaml
  flows:
  - flow: authorizationCode
    authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize
    tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token
  description: OAuth 2.0 via Microsoft Identity Platform for Office Add-ins.
scopes:
- scope: Files.Read
  description: Read the signed-in user's files.
  flows: [authorizationCode]
  sources: [openapi/microsoft-word-graph-api.yaml]
- scope: Files.Read.All
  description: Read all files the signed-in user can access.
  flows: [authorizationCode]
  sources: [openapi/microsoft-word-graph-api.yaml]
- scope: Files.ReadWrite
  description: Read and write the signed-in user's files.
  flows: [authorizationCode]
  sources: [openapi/microsoft-word-graph-api.yaml, openapi/microsoft-word-javascript-api.yaml]
- scope: Files.ReadWrite.All
  description: Read and write all files the signed-in user can access.
  flows: [authorizationCode]
  sources: [openapi/microsoft-word-graph-api.yaml]
- scope: Files.ReadWrite.AppFolder
  description: Read and write files in the application's dedicated folder.
  flows: [authorizationCode]
  sources: [docs]
- scope: Sites.Read.All
  description: Read items in all SharePoint site collections the user can access (SharePoint document libraries).
  flows: [authorizationCode]
  sources: [docs]
- scope: Sites.ReadWrite.All
  description: Read and write items in all SharePoint site collections (admin consent typically required).
  flows: [authorizationCode]
  sources: [docs]
- scope: User.Read
  description: Sign in and read the signed-in user's profile (baseline scope requested at login).
  flows: [authorizationCode]
  sources: [docs]