OAuth lets you give an app scoped access to your account without handing over your password.
Key points
- OAuth 2.0 is specified in RFC 6749; the app receives an access token instead of the user's credentials [1].
- Scopes limit what the token can do, for example read mail, send mail or read contacts, and users see them on the consent screen [2].
- PKCE, defined in RFC 7636, protects the authorization code flow against interception and is now recommended for all clients [3][4].
- Access tokens are short-lived; refresh tokens let the app get new ones until the user revokes access [1].
- Tools that send from a connected mailbox, or run Email Sync with Gmail or Outlook, typically connect through OAuth [2][5].
How OAuth works
OAuth separates the user's identity from the access an app receives. In the common authorization code flow, the app sends the user to the provider, such as Google or Microsoft. The user signs in there, not in the app, and sees which permissions the app is requesting. If they agree, the provider redirects back with a short-lived code, and the app exchanges that code for an access token and usually a refresh token [1]. The app then calls the provider's REST API with the access token. RFC 7636 adds PKCE, a one-time secret that proves the same app started and finished the flow, which blocks code interception [3]. The current OAuth security guidance, RFC 9700, recommends PKCE for all clients [4].
Scopes and consent
Scopes define what a token can do. Google's OAuth documentation encourages apps to request only the scopes they need, and to request them at the point where they are needed, so users can make informed choices [2]. For email tools, the difference between reading metadata, reading full messages and sending mail is significant, and providers classify some mail scopes as sensitive or restricted, with extra review for apps that request them. Microsoft's identity platform follows the same model with its own permission names [5]. Users can revoke access at any time from their account settings, which invalidates the app's tokens. That makes OAuth safer than storing a password, which grants full access and must be changed everywhere if it leaks.
OAuth in sales tools
Most sales tools that touch a mailbox or CRM (Customer Relationship Management) use OAuth. Connecting a Gmail or Outlook account lets a tool send email from the user's own address, read replies over IMAP or the provider's API for Reply Detection, and keep threads in step through Email Sync. Sending from a real, authenticated mailbox helps deliverability, because messages carry the domain's own SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail) setup. Teams should review which scopes each tool requests, prefer tools that ask for the minimum, put a Data Processing Agreement (DPA) in place where the GDPR applies, and remove access for tools no longer in use. OAuth tokens are secrets just like an API Key, so the tools that hold them should encrypt them and limit who can reach them. If a token stops working, reconnecting through the consent screen issues a new one.
- RFC 6749: The OAuth 2.0 Authorization Framework — IETF
- Using OAuth 2.0 to Access Google APIs — Google for Developers
- RFC 7636: Proof Key for Code Exchange by OAuth Public Clients — IETF
- RFC 9700: Best Current Practice for OAuth 2.0 Security — IETF
- Microsoft identity platform and OAuth 2.0 authorization code flow — Microsoft Learn
Related terms
Outreach without the busywork.
PineLead finds new B2B prospects every day, qualifies them against your criteria and writes the first email in your voice. You approve — PineLead sends.
Start free with 100 credits →