Microsoft SharePoint · OAuth Scopes

Microsoft SharePoint OAuth Scopes

OAuth 2.0 searched

Microsoft SharePoint publishes 5 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Microsoft SharePoint API on a user’s behalf.

Tokens are issued from https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CollaborationDocument ManagementEnterprise Content ManagementIntranetMicrosoft
Scopes: 5 Flows: authorizationCode Method: searched

OAuth endpoints

Authorization URL
https://login.microsoftonline.com/{tenant}/oauth2/v2.0/authorize
Token URL
https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token
Flows
authorizationCode

Scopes (5)

ScopeDescriptionFlows
Sites.FullControl.All Full control of all site collections. authorizationCode
Sites.Manage.All Create, edit, and delete items and lists. authorizationCode
Sites.Read.All Read all site collections. authorizationCode
Sites.ReadWrite.All Read and write all site collections. authorizationCode
Sites.Selected Access only to specific SharePoint site collections granted explicitly by an admin (per-site authorization). authorizationCode

Source

OAuth Scopes

Raw ↑
generated: '2026-06-20'
method: searched
source: openapi/sharepoint-rest-api.yaml
docs: https://learn.microsoft.com/en-us/graph/permissions-reference#sites-permissions
notes: >-
  SharePoint permissions are Microsoft Graph / Microsoft Entra scopes. The Sites.* set below
  is documented in the Microsoft Graph permissions reference. Both delegated and application
  permission variants exist; Sites.Selected additionally supports per-site granular grants.
schemes:
- name: oauth2
  source: openapi/sharepoint-rest-api.yaml
  flows:
  - flow: authorizationCode
    authorizationUrl: https://login.microsoftonline.com/{tenant}/oauth2/v2.0/authorize
    tokenUrl: https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token
  description: OAuth 2.0 via Azure AD / Microsoft Identity Platform.
scopes:
- scope: Sites.FullControl.All
  description: Full control of all site collections.
  flows:
  - authorizationCode
  sources:
  - openapi/sharepoint-rest-api.yaml
- scope: Sites.Manage.All
  description: Create, edit, and delete items and lists.
  flows:
  - authorizationCode
  sources:
  - openapi/sharepoint-rest-api.yaml
- scope: Sites.Read.All
  description: Read all site collections.
  flows:
  - authorizationCode
  sources:
  - openapi/sharepoint-rest-api.yaml
- scope: Sites.ReadWrite.All
  description: Read and write all site collections.
  flows:
  - authorizationCode
  sources:
  - openapi/sharepoint-rest-api.yaml
- scope: Sites.Selected
  description: Access only to specific SharePoint site collections granted explicitly by an admin (per-site authorization).
  flows:
  - authorizationCode
  sources:
  - https://learn.microsoft.com/en-us/graph/permissions-reference#sites-permissions