invalid_scope 🔐 Authentication

OAuth 2.0 Error: invalid_scope / insufficient_scope

The requested scope is unknown or not allowed for this client — or the token lacks the scope the API endpoint requires.

Seen on: Microsoft Google REST API

Meaning

invalid_scope comes from the authorization/token endpoint when you ask for scopes that don’t exist or aren’t granted to the app. insufficient_scope (often with 403) comes from a resource API when the token is valid but doesn’t carry the needed permission.

Common causes

  • Typo or wrong format (space-separated in OAuth; some providers use full URIs like https://graph.microsoft.com/.default)
  • Scope not enabled/added for the app in the provider console
  • Admin consent required but not granted (Microsoft, Google Workspace)
  • Mixing scopes for different resources in one request
  • Token issued before new scopes were added — user must re-consent

⚡ Quick fix

  1. Copy scope names exactly from the provider docs
  2. Add/enable the scope (API permissions) for the app and grant admin consent if needed
  3. Request a new token after changing scopes (and re-prompt consent)
  4. Decode the access token and check the scope/scp claim

Detailed fix by platform

Microsoft

  1. App registration → API permissions → add the permission → “Grant admin consent”. Client-credential flows must request <resource>/.default.

Google

  1. Enable the API in the Cloud project and add the scope on the OAuth consent screen; sensitive scopes may need verification.

How to diagnose

  1. Where — Token endpoint (invalid_scope) or resource API (insufficient_scope)?
  2. Requested — Exact scope string sent
  3. Granted — scope/scp claim in the token
  4. Consent — Has the user/admin consented to the new scopes?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.