---
updatedAt: 2025-09-16T01:45:51.000Z
agentTools:
  projectIndex: https://developers.gorgias.com/llms.txt
---

# OAuth2 Scopes

OAuth2 scopes allow to limit your app's access to Gorgias user’s account data.

The following scopes can be defined programmatically:

## Basic scopes

| Name    | Description                                                                            |
| :------ | :------------------------------------------------------------------------------------- |
| openid  | Scope required to "login" with Gorgias. Allows Gorgias to act as a OpenID provider.    |
| email   | User email address.                                                                    |
| profile | Basic user information such as their name.                                             |
| offline | Scope required to use a `refresh_token` - needed to deal with expiring `access_token`. |

## Gorgias scopes

<Table align={["left","left"]}>
  <thead>
    <tr>
      <th>
        Name
      </th>

      <th>
        Description
      </th>
    </tr>
  </thead>

  <tbody>
    <tr>
      <td>
        account:read
        account:write
      </td>

      <td>
        Information about your account, including account-wide settings like business hours. The write scope can be used to update the account owner.
      </td>
    </tr>

    <tr>
      <td>
        users:read\
        users:write
      </td>

      <td>
        Users of your helpdesk and any data associated with them, including: email address; first name; last name; bio; role (basic agent, admin, etc.); teams.
      </td>
    </tr>

    <tr>
      <td>
        customers:read\
        customers:write
      </td>

      <td>
        Data associated with your customers, including: email address; first name; last name; language; notes; data received via integrations (such as Shopify).
      </td>
    </tr>

    <tr>
      <td>
        tickets:read\
        tickets:write
      </td>

      <td>
        Ticket views and their settings, as well as tickets with their content, including messages, tags, assignees, etc.
      </td>
    </tr>

    <tr>
      <td>
        custom\_fields:read\
        custom\_fields:write
      </td>

      <td>
        Custom fields and their configuration.
      </td>
    </tr>

    <tr>
      <td>
        events:read\
        events:write
      </td>

      <td>
        Changes that are being tracked for your account, including events like: ticket created/updated/closed, etc; user created/updated/deleted, etc; rule created/updated/deleted, etc.
      </td>
    </tr>

    <tr>
      <td>
        integrations:read\
        integrations:write
      </td>

      <td>
        HTTP integrations, native integrations, and widgets that are connected to your account.
      </td>
    </tr>

    <tr>
      <td>
        jobs:read\
        jobs:write
      </td>

      <td>
        E.g.: closing 10k tickets, exporting 500k tickets, etc.
      </td>
    </tr>

    <tr>
      <td>
        macros:read\
        macros:write
      </td>

      <td>
        Macros and their configuration.
      </td>
    </tr>

    <tr>
      <td>
        rules:read\
        rules:write
      </td>

      <td>
        Rules and their configuration.
      </td>
    </tr>

    <tr>
      <td>
        satisfaction\_survey:read\
        satisfaction\_survey:write
      </td>

      <td>
        Satisfaction surveys that have been or will be sent to your customers.
      </td>
    </tr>

    <tr>
      <td>
        statistics:read
      </td>

      <td>
        Support metrics calculated for your account.
      </td>
    </tr>

    <tr>
      <td>
        tags:read\
        tags:write
      </td>

      <td>
        Tags that can be added to tickets.
      </td>
    </tr>

    <tr>
      <td>
        apps:read\
        apps:write
      </td>

      <td>
        List and uninstall third party Apps.
      </td>
    </tr>
  </tbody>
</Table>

## Deprecated scopes

<Table align={["left","left"]}>
  <thead>
    <tr>
      <th>
        Name
      </th>

      <th>
        Description
      </th>
    </tr>
  </thead>

  <tbody>
    <tr>
      <td>
        write:all
      </td>

      <td>
        Read and Write permissions to all resources accessible by the user's grant.  

        ***Note that that this is a temporary permission and will be removed in the future in favor of more granular scopes. We'll notify you well in advance when that happens to migrate.***
      </td>
    </tr>
  </tbody>
</Table>