Trust Center
OAuth scope and capability directory
The resources Trytracegrid reads, the actions it may perform, and the limitations that apply to each provider.
Default behavior
Connections start in read_only mode. Where a provider supports separate scopes, extra write scopes require a separate reauthorization for a controlled test workspace. Google Ads exposes a combined OAuth scope; Trytracegrid enforces read-only behavior in its own server authorization layer.
| Provider | Read access | Beta writes | Verification | Rollback |
|---|---|---|---|---|
| Google Tag Manager tagmanager.readonly | Containers, versions, tags, triggers, and variables | Create an isolated draft workspace; Publish an approved version in test workspaces | Live-version read-back; Browser request observation | limited Publishing and prior-version restoration require separate approvals, an enabled test workspace, and successful controlled-account verification. |
| Google Analytics 4 analytics.readonly | Properties, streams, events, and key-event configuration | None | Admin configuration; Data API reporting | unavailable GA4 administration writes are disabled during the beta. |
| Google Ads adwords (provider scope includes mutation capability) | Accounts, serving ads, conversion actions, and URL tracking fields | Approved UTM fields in test workspaces | Provider field read-back | limited Google provides a combined Ads scope; Trytracegrid enforces read-only behavior on its server. Restoration remains beta-gated until controlled-account verification passes. |
| Meta Ads ads_read | Ad accounts, serving ads, URL tags, and catalog summaries | None | Marketing API configuration reads | unavailable Published creative replacement is not automated during the beta. |
| TikTok Ads Advertiser read permissions granted in TikTok Business Center | Advertisers, serving ads, URL parameters, and catalog summaries | Approved UTM fields in test workspaces | Provider field read-back | limited Write access remains feature-flagged until provider rollback contract tests pass. |
| Shopify read_themes, read_products, read_content | Products, content, and theme tracking markers | None | Storefront scan | unavailable Theme and pixel writes are disabled during the beta. |
| Webflow sites:read, pages:read, custom_code:read | Sites, pages, and custom-code inventory | None | Published-site browser scan | unavailable Custom-code writes are disabled until restore testing is complete. |
Before authorization
The connection screen displays the requested scopes, the selected resources, and the actions available in the selected access mode. Revoking or disconnecting a provider stops future access and removes the stored credential.