Platform capability
Continuous OAuth Audit
ScopeMantle continuously inventories every third-party OAuth grant across Okta and Google Workspace — scopes, users, timestamps, and exportable evidence.
Start a 30-day trial01 · OAUTH AUDIT
Continuous OAuth Audit
Most security teams are flying blind on third-party OAuth. The grants weren't really shadow — it's just that no tool was responsible for keeping the list current. ScopeMantle fixes that by treating your IdP as the source of truth and continuously pulling every OAuth grant, every connected service, every domain-wide install, without agents, without proxies, without anything you have to maintain.
We start with Okta and Google Workspace because that's where 80% of the signal lives. Within minutes of connecting, you have a complete inventory: app name, source, user count, scopes granted, first-seen timestamp, privacy-policy URL, and a risk tag derived from what each scope actually lets the app do. Microsoft Entra is on the roadmap; we'll connect to it the same way — read-only, revocable, no agents.
- Continuous OAuth grant inventory across Okta, Google Workspace, and Entra (roadmap)
- Full scope extraction — every grant, every user, every timestamp
- Per-app user rosters with role and last-active context from your IdP
- Policy-aware duplicate detection across sources (one Slack, not three)
- Privacy-policy URL captured and version-tracked per vendor
- Stale-token sweeps — flag unused 90+ day grants automatically
- CSV, JSON, and direct SIEM export of the live inventory
OAuth scopes · 21 granted
+ 15 more scopes
Users with access · 1,247
Privacy analysis · refreshed 6d ago
Frequently asked
Platform — common questions
Find the Context.ai in your org before the attacker does.
15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.
Book a demo to see the inventory on your own tenant.