[{"data":1,"prerenderedAt":147},["ShallowReactive",2],{"glossary-en-drive-file-scope":3},{"id":4,"title":5,"body":6,"category":137,"description":138,"draft":139,"extension":140,"meta":141,"navigation":142,"path":143,"seo":144,"stem":145,"__hash__":146},"glossary_en\u002Fglossary\u002Fdrive-file-scope.md","What is the drive.file scope?",{"type":7,"value":8,"toc":127},"minimark",[9,21,26,29,64,70,74,80,95,99,109,114],[10,11,12,13,17,18,20],"p",{},"The ",[14,15,16],"code",{},"drive.file"," scope is a Google OAuth permission that gives an app access only to the specific Google Drive files the user has opened or picked with that app, plus files the app itself created. An app with ",[14,19,16],{}," cannot list, read, or search the rest of your Drive. It is Google's recommended scope for Drive integrations, and the narrowest one that still lets an app read and modify files.",[22,23,25],"h2",{"id":24},"googles-scope-tiers-in-one-minute","Google's scope tiers, in one minute",[10,27,28],{},"When a third-party app asks to connect to your Google account, what it can do is defined by OAuth scopes. Google classifies them in three tiers:",[30,31,32,43,49],"ul",{},[33,34,35,39,40,42],"li",{},[36,37,38],"strong",{},"Non-sensitive"," scopes grant narrow access. ",[14,41,16],{}," sits here: per-file, user-granted, invisible beyond what you hand over. The consent screen for it is correspondingly mild.",[33,44,45,48],{},[36,46,47],{},"Sensitive"," scopes grant broader access to user data and require extra app verification by Google.",[33,50,51,54,55,58,59,63],{},[36,52,53],{},"Restricted"," scopes are the broadest. The full ",[14,56,57],{},"drive"," scope — read and write access to ",[60,61,62],"em",{},"all"," files in your Drive — is in this tier, and apps requesting it go through Google's most demanding review, including independent security assessment requirements.",[10,65,66,67,69],{},"In practice you can read an app's reach straight off its consent screen: \"See and manage all of your Drive files\" means the full scope; per-file wording means ",[14,68,16],{},".",[22,71,73],{"id":72},"how-per-file-access-works-in-practice","How per-file access works in practice",[10,75,76,77,79],{},"With ",[14,78,16],{},", the handover happens through the Google Drive picker — the standard file-selection dialog. You pick three folders of scans; the app gains access to those, and only those. Files it creates (a sorted copy, an export) it can also touch. Everything else in your Drive doesn't exist as far as the app is concerned, even after you've used it for months.",[10,81,82,83,88,89,91,92,94],{},"This is why the scope matters as trust content, not just as a technical detail. An ",[84,85,87],"a",{"href":86},"\u002Fglossary\u002Fai-file-organizer-for-google-drive","AI file organizer for Google Drive"," must, by definition, read your documents to classify them. The scope determines the blast radius of that trust: with ",[14,90,16],{}," you're trusting the app with the batch you picked, not with your tax returns, payslips, and ten years of photos. Sorters is built on ",[14,93,16],{}," for exactly this reason — it sorts the files you select in the picker and can't see anything else. We read your files to classify them. Nothing is kept after the file is sorted: no copies, no logs of content.",[22,96,98],{"id":97},"when-apps-legitimately-need-the-full-scope","When apps legitimately need the full scope",[10,100,101,102,104,105,108],{},"The full ",[14,103,57],{}," scope isn't a red flag by itself — it's a trade-off. A duplicate finder has to compare every file against every other; a whole-Drive backup tool has to read everything; a storage analyzer has to list it all. None of those jobs are possible per-file. The question to ask is whether the app's job actually requires whole-Drive visibility. A tool that sorts the files you give it doesn't; a tool that scans for what you ",[60,106,107],{},"didn't"," give it does.",[110,111,113],"h3",{"id":112},"related","Related",[10,115,116,117,121,122,126],{},"See ",[84,118,120],{"href":119},"\u002Fglossary\u002Fauto-sort-files-in-google-drive","how to auto-sort files in Google Drive"," for what sorting under a per-file permission looks like in practice, and ",[84,123,125],{"href":124},"\u002Fglossary\u002Fai-file-organizer","AI file organizer"," for what these tools do with the access once granted.",{"title":128,"searchDepth":129,"depth":129,"links":130},"",2,[131,132,133],{"id":24,"depth":129,"text":25},{"id":72,"depth":129,"text":73},{"id":97,"depth":129,"text":98,"children":134},[135],{"id":112,"depth":136,"text":113},3,"Definitions","The drive.file scope is Google's per-file Drive permission — an app sees only files you pick or it created. What that means for add-on privacy.",false,"md",{},true,"\u002Fglossary\u002Fdrive-file-scope",{"title":5,"description":138},"glossary\u002Fdrive-file-scope","FmCZujYeLZkNvxTuZT4GL573c-5ZYuV7nlxRLIEgitI",1785276343854]