OAuth scopes we request
Exactly what permission each integration asks for, and why.
Omesta requests the minimum scopes needed to do its job. And no more. Here's the complete list per integration.
Stripe
Read-only: charges, subscriptions, invoices, customers, disputes. Write (only if automation is enabled): retry specific charge, send specific dunning email.
Meta Ads
ads_management, ads_read, pages_show_list, pages_read_engagement. Reads campaigns, ad sets, ads, creatives, and Page health. The management scope is needed for Autopilot ad pausing. Writes only happen if you turn that module on.
Google Ads
adwords (full). Reads campaign / ad-group / ad performance and powers Autopilot ad pausing when enabled. Search Console + Indexing scopes were dropped. Connect Search Console separately if you want SEO features.
TikTok Ads
TikTok Business management scope. Campaign and ad performance reads plus the ability to pause underperforming ads via Autopilot when enabled.
Shopify
read_orders, read_products, read_customers, read_refunds. Installed as a private app per store; no write scopes.
Google Analytics 4
analytics.readonly. Read-only access to the properties you select during connection.
For full detail on data fields accessed per scope, see our Integration Data Disclosure page.