Skip to main content
Hookfish uses two independent scope systems.

Resource scopes

A broker resource scope grants either one exact path or an explicit subtree:
user/personal/gmail grants only that exact connection. It does not grant user/personal/gmail/mcp. user/personal/** grants the namespace itself and all descendants. Use ** only for root-level administration. This distinction lets a service receive access to one connection without automatically receiving every connection below a similarly named folder.

Provider scopes

Provider scopes control what an upstream OAuth credential may do:
The provider implementation defines these values. For MCP, scopes supplied with the resource URL become the connection’s immutable MCP configuration and the requested upstream permissions. Hookfish records requested and granted provider scopes separately. Access with a scope that was never requested starts authorization. If the provider already declined that scope, access returns scope_not_granted instead of opening a consent loop. You can explicitly retry with connections.authorize() after the user changes their provider permissions. See Token scoping for delegation and expiry.