OAuth 2.0 Error: invalid_scope / insufficient_scope
The requested scope is unknown or not allowed for this client — or the token lacks the scope the API endpoint requires.
Meaning
invalid_scope comes from the authorization/token endpoint when you ask for scopes that don’t exist or aren’t granted to the app. insufficient_scope (often with 403) comes from a resource API when the token is valid but doesn’t carry the needed permission.
Common causes
- Typo or wrong format (space-separated in OAuth; some providers use full URIs like
https://graph.microsoft.com/.default) - Scope not enabled/added for the app in the provider console
- Admin consent required but not granted (Microsoft, Google Workspace)
- Mixing scopes for different resources in one request
- Token issued before new scopes were added — user must re-consent
⚡ Quick fix
- Copy scope names exactly from the provider docs
- Add/enable the scope (API permissions) for the app and grant admin consent if needed
- Request a new token after changing scopes (and re-prompt consent)
- Decode the access token and check the
scope/scpclaim
Detailed fix by platform
Microsoft
- App registration → API permissions → add the permission → “Grant admin consent”. Client-credential flows must request
<resource>/.default.
- Enable the API in the Cloud project and add the scope on the OAuth consent screen; sensitive scopes may need verification.
How to diagnose
- Where — Token endpoint (invalid_scope) or resource API (insufficient_scope)?
- Requested — Exact scope string sent
- Granted — scope/scp claim in the token
- Consent — Has the user/admin consented to the new scopes?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026