What permissions can I grant a Connected App?

Each connection is granted a specific set of permissions, so you can limit what it is allowed to do.

Files — each level includes everything before it:

  1. Read files — view and download your files.
  2. Read & write files — also upload files, save shared files, copy, move, rename, and create folders.
  3. Manage files — also move files and folders to Trash and restore them from Trash.
  4. Permanently delete — also permanently delete files and empty Trash. These actions cannot be undone, so this permission is never granted by default.

Services:

  • Cloud Download — create offline download tasks.
  • Share — create and manage sharing links.

Account:

  • Invite — create invitation codes and links.
  • Account settings — view and change your profile and preferences.

Different connection types have different defaults. For example, a Personal Access Token starts with Read files only because it is intended for unattended use. You will see the requested permissions before you confirm a connection, and you can review or remove the connection at any time from Connected Apps.

Permanently delete and Invite are not available to every connection type. Personal Access Tokens and PikPak MCP, for example, cannot be granted these permissions.

WebDAV uses the fixed Manage files permission because the WebDAV protocol cannot apply separate permissions to individual file operations. It cannot permanently delete files or empty Trash.