Revoking access to your Google account helps you control which apps, sites, and devices can view or use your data. This evergreen explainer walks through how to review connected services, remove account access, and understand what changes when you revoke access. Whether you are responding to a security concern or cleaning up old authorizations, the steps below support lasting account hygiene and clearer visibility into third-party data sharing.
What Happens When You Revoke Access to a Google Account
Revoking access removes an app or service’s ability to use your Google Account credentials and typically limits its access to data previously permitted via scopes. Common effects include:
- The app can no longer sign you in using Google unless you reauthorize.
- Data previously shared, such as profile information or email, is no longer available to that app until you grant it again.
- Tokens used for background sync or API calls are invalidated, which may stop connected features from working.
Note that revoking access on one device or client does not always remove all device-level permissions, such as Android device administrator rights, which may require separate steps.
Where to Find Connected Apps and Services
Review Third-Party Access in Google Account Settings
Google consolidates most third-party app and service connections in one place. From a signed-in browser, open your Google Account, then go to Security or Manage Your Google Account, and look for Connected apps & sites or Third-party access. Here you can see each connection, the data scopes requested, and the last activity timestamp.
Check Apps with Account Access on Mobile and Desktop
Device-specific sign-in prompts and native app access may appear in separate settings depending on your operating system. On Android, review device administrator apps and Google Play Services permissions. On iOS and macOS, check Settings for apps using "Continue with Google" and their respective system privacy settings. Desktop browsers often store site-specific sign-in states in password managers or profile permissions, which should be audited separately.
How to Revoke Access to Google Account Step by Step
- Open a browser and go to accounts.google.com.
- Sign in with the account you want to manage.
- Navigate to Security, then Connected apps & site access.
- Under "Third-party apps with account access," locate the app or service you want to revoke.
- Select it and choose Remove Access or Revoke.
- Confirm the action when prompted.
For device-specific restrictions, such as Android device admin or macOS login items, open your device settings, locate the app or service, and select Remove or Disable. If you use two-factor authentication, ensure you can re-authenticate before revoking, as some apps may block sign-in without a second factor.
What Data and Permissions Are Affected
When you revoke access, the immediate impact is on application-specific permissions rather than your core Google Account profile data. Commonly affected items include:
- Read access to your email address and basic profile info.
- Permission to send emails on your behalf via SMTP or APIs.
- Access to Drive files shared with the app or used in integration workflows.
- Calendar read or write permissions granted to connected productivity tools.
Core account details, such as your primary email address, recovery information, and billing history, typically remain under your direct control and are not deleted by revoking third-party access. However, if an app stored copies of your data externally, those copies will not be removed by this process.
Example Scopes Commonly Seen and Their Impact
| Scope or Permission | What It Allows | Revocation Effect |
|---|---|---|
| https://www.googleapis.com/auth/userinfo.email | Access to your email address | App can no longer retrieve your email |
| https://www.googleapis.com/auth/calendar.readonly | Read-only calendar events | App can no longer view your calendar |
| https://www.googleapis.com/auth/drive.file | Access to files created or opened by the app | App loses access to those Drive files |
| https://www.googleapis.com/auth/contacts.readonly | Read your contacts | App can no longer sync or read contacts |
Best Practices for Managing Access Over Time
Regular reviews reduce risk and improve visibility. Aim to audit connected apps every few months, especially after a device is lost, sold, or replaced. Use app-specific passwords for legacy services when supported, and prefer OAuth revocation over password changes unless necessary. Enable two-factor authentication to ensure that revoked sessions cannot be reused without additional verification. Export or download important data from a service before revoking access if you rely on synced content stored in that app.
Troubleshooting Common Issues After Revoking Access
If an app continues to show connected status or prompts for sign-in after revocation, clear cached tokens, sign out of all sessions in the app, and revoke any device-level permissions. Some services require manual deletion of stored connections or re-linking via OAuth to restore functionality. If synced content becomes inaccessible, check whether local files exist on your device or in alternative cloud storage, since revoking app access does not delete files already downloaded.