CONNECTED APPS & PERMISSIONS: WHAT HAS ACCESS TO YOUR ACCOUNT?
Many services allow external applications, websites and tools to connect to an account.
This can make life easier, but every connection creates another relationship that deserves attention.
The central principle is:
DO NOT GIVE AN APPLICATION MORE ACCESS THAN YOU UNDERSTAND AND ACTUALLY NEED.
1. WHAT IS A CONNECTED APPLICATION?
A connected application is an external service that has been granted some form of access to an account.
For example, you may see:
“Continue with another provider.”
or
“Allow this application to access your account.”
The exact access depends on the service and permissions granted.
2. WHAT IS A PERMISSION?
A permission describes what an application is allowed to access or do.
Depending on the service, permissions may include:
- View profile information
- Read files
- Create or modify content
- Send messages
- Access contacts
- Manage calendars
- Perform actions on your behalf
Not all permissions have the same risk.
3. READ THE AUTHORISATION SCREEN
Do not click “Allow” automatically.
Before granting access, ask:
- What application is requesting access?
- Who operates it?
- What information can it access?
- What actions can it perform?
- Does it actually need those permissions?
- Did I intentionally start this connection?
If you do not understand a permission, pause before granting it.
4. LEAST PRIVILEGE
Least privilege means giving an application only the access required for its legitimate purpose.
If an application only needs to read a limited type of information, broad access may be unnecessary.
Where the service allows permission choices, select the narrowest appropriate option.
Less unnecessary access means less potential impact if the application is compromised or misused.
5. WHY OLD CONNECTIONS MATTER
People often connect an application once and forget about it.
Years later:
- The application may no longer be used.
- The company may have changed ownership.
- The account may have been abandoned.
- The integration may have become unnecessary.
- The permissions may have become broader than you remember.
Old access creates unnecessary exposure.
6. REVIEW CONNECTED APPLICATIONS
For important accounts, periodically open the official security, privacy or connected-applications settings.
Look for:
- Applications you recognise and still use
- Applications you no longer use
- Applications you do not recognise
- Broad permissions
- Old integrations
- Unknown tokens or access grants
Remove access that is no longer necessary through the official controls.
7. A FAMILIAR LOGO IS NOT PROOF
An application may use a familiar name, logo or colour scheme.
Branding can be copied.
Before authorising access, verify the application through the official service and consider whether the requested permissions make sense.
8. “SIGN IN WITH” SERVICES
Sign-in integrations can provide convenient authentication, but read the authorisation information carefully.
The important question is not merely:
“Can I sign in quickly?”
Ask:
“WHAT AM I ALLOWING THIS SERVICE TO ACCESS OR DO?”
9. OAUTH AND ACCESS TOKENS
Many modern services use authorisation systems that allow an application to access defined resources without receiving your normal account password.
This can improve security because you do not have to give the external application your password.
But an access token or authorisation can still be sensitive.
Treat access grants as security relationships that should be reviewed and revoked when no longer needed.
10. API KEYS AND APP PASSWORDS
Some services use API keys, access tokens or app passwords to allow software to connect.
These may provide significant access.
Never publish sensitive keys in:
- Public repositories
- Screenshots
- Public documents
- Chat messages
- Client-side code when the credential is intended to remain secret
If a secret is exposed, follow the service's official process for revoking and replacing it.
11. CONNECTED APPS AFTER AN ACCOUNT COMPROMISE
If an account may have been compromised, connected applications deserve special attention.
An attacker may have added or authorised an application or created another access pathway.
Changing the password alone may not remove every token or authorisation.
Review and revoke unfamiliar access through the official account controls.
12. CONNECTED APPLICATIONS AND EMAIL
Email accounts can be especially sensitive because an authorised application may be able to read or act on messages depending on the permissions granted.
After compromise, check for:
- Unfamiliar mail applications
- Forwarding rules
- Filters
- Connected services
- App passwords
- Access tokens
13. CONNECTED APPLICATIONS AND CLOUD STORAGE
Cloud storage often contains documents, photos, business records and personal information.
An application with broad cloud access may have significant visibility into your digital life.
Review whether old integrations still need access.
14. CONNECTED APPLICATIONS AND SOCIAL MEDIA
Some applications can publish content, read profile information or perform actions on social-media accounts.
If an unknown integration is connected, revoke it through the official account settings and review recent activity.
Do not assume that a strange post is merely a harmless software error.
15. CONNECTED APPLICATIONS AND CRYPTO
Cryptocurrency users require additional caution when connecting wallets to websites and decentralised applications.
A wallet connection, signature, approval or transaction can have consequences depending on what is requested.
Before approving:
- Verify the website.
- Confirm the correct network.
- Understand the requested action.
- Check the asset involved.
- Review permissions or approvals where the wallet provides that information.
NEVER SHARE A WALLET RECOVERY PHRASE WITH AN APPLICATION OR PERSON CLAIMING IT IS REQUIRED FOR CONNECTION OR VERIFICATION.
16. DO NOT CONFUSE CONNECTION WITH TRUST
A website can be connected to an account without being permanently trustworthy.
A familiar service can also be compromised.
The fact that an application has been used before does not mean every future request from it should be approved without review.
17. HOW TO REVOKE ACCESS SAFELY
A safe general process is:
- Open the official application or website yourself.
- Go to security, privacy or connected-app settings.
- Identify the application.
- Review the permissions.
- Revoke unnecessary or unfamiliar access.
- Review related sessions or tokens where available.
- Change the password if compromise is suspected.
- Re-enable only trusted integrations you actually need.
18. WHAT IF YOU DO NOT RECOGNISE AN APPLICATION?
Do not investigate through links in a suspicious message.
Instead:
- Open the official service yourself.
- Confirm the application or access grant.
- Revoke it if it is unfamiliar or unnecessary.
- Review the account for other unusual changes.
- Review password, MFA and recovery settings.
- Review active sessions.
19. COMMON MISTAKES
Mistake 1: “I connected it once, so it is safe forever.”
Why this is dangerous: Access can remain after you stop using the application.
Mistake 2: “The logo looks familiar.”
Why this is dangerous: Branding can be copied.
Mistake 3: “I will approve every permission so setup is faster.”
Why this is dangerous: You may grant unnecessary access.
Mistake 4: “I changed my password, so every connection is gone.”
Why this is dangerous: Tokens or authorisations may persist depending on the service.
Mistake 5: “This wallet request is safe because the website looks professional.”
Why this is dangerous: Appearance does not prove that a transaction or permission request is legitimate.
20. STEP-BY-STEP: REVIEW AND REVOKE CONNECTED APPS
Use this general process to review third-party applications and permissions. Exact menu names vary by service. Use the official app or website rather than links from suspicious messages.
STEP 1 — OPEN THE OFFICIAL SERVICE
Open the account through the official application or website yourself.
STEP 2 — OPEN SECURITY, PRIVACY OR CONNECTED-APP SETTINGS
Look for Connected Apps, Third-Party Access, Apps & Services, Authorized Applications, Permissions, Integrations or a similar section.
STEP 3 — REVIEW EACH CONNECTION
Check the application name, operator where shown, date or last-used information and the permissions it has been granted.
STEP 4 — ASK WHETHER YOU STILL NEED IT
For each connection, ask: Do I recognize it? Do I still use it? Did I intentionally authorize it? Do I understand what it can access or do?
STEP 5 — CHECK THE SCOPE OF ACCESS
Pay particular attention to broad permissions, access to email or cloud files, ability to send or modify content, financial permissions, and other actions performed on your behalf.
STEP 6 — REVOKE UNNECESSARY OR UNFAMILIAR ACCESS
Use the official Remove Access, Revoke, Disconnect or equivalent control. Do not follow a link supplied by the application or by a suspicious message simply to revoke access.
STEP 7 — REVIEW RELATED ACCESS
Where the service provides them, review access tokens, app passwords, API keys, sessions and other connected pathways. Revoking one application does not necessarily remove every other form of access.
STEP 8 — IF COMPROMISE IS SUSPECTED
Secure the account through the official service. Review the password, MFA, recovery methods, active sessions, forwarding rules and other security settings that may have been changed.
STEP 9 — VERIFY THE RESULT
Return to the connected-applications or permissions page and confirm that the unwanted application or access grant has been removed.
21. YOUR CONNECTED-APPS CHECKLIST
□ Do I know which applications have access to this account? □ Do I still use each connected application? □ Do I understand the permissions granted? □ Are any permissions broader than necessary? □ Are there unfamiliar applications or tokens? □ Have I removed old integrations? □ Do I know how to revoke access? □ Have I reviewed connected access after a suspected compromise? □ For crypto activity, do I verify the website and requested action before approving?
22. A PRACTICAL EXAMPLE
You receive a message asking you to “connect your account to claim a reward.”
The page uses a familiar logo and asks for broad permissions.
The safer response is not to approve the request because the branding looks convincing.
Instead:
STOP. Verify the official promotion independently. Open the official service yourself. Read the permissions. Ask whether the connection is actually necessary.
23. IF YOU REMEMBER ONLY ONE THING
Every connected application creates another security relationship.
Keep those relationships intentional. Review them. Remove unnecessary access. Do not approve permissions you do not understand.
