
Check which apps and sites are logged into your Google account (and revoke access)
Published Jul 24, 2026
Every time you click “Sign in with Google” on some app or website, you’re not just logging in once — you’re granting that app standing access to your Google account, which stays active until you manually revoke it. Most people never check this list, and it tends to grow for years: an app you tried once in 2019, a browser extension you forgot you installed, a hackathon project that asked for your contacts. Here’s exactly where to look and how to clean it up.
Where to see every app connected to your Google account
Go to myaccount.google.com/permissions (or: Google Account → Security → “Third-party apps with account access”).
This page lists every app and site that has ever been granted OAuth access to your Google account — not just the ones you’re actively using. Click any entry to see exactly what it can access: your email address, your profile photo, your contacts, your Google Drive files, your Calendar, or (much more rarely, but worth checking) full account access.
What the permission levels actually mean
Google groups access into rough tiers, and the difference matters:
- Basic profile info (name, email, photo) — low risk. This is what almost every “Sign in with Google” button requests, equivalent to the app knowing who you are.
- See, edit, create, or delete your Google Drive files — this is a meaningfully bigger grant. An app with this permission can read documents you never intended to share with it.
- Read, send, delete, and manage your email — the highest-risk common permission. Very few legitimate apps need this; if something you don’t recognize has it, revoke immediately.
- Full account access — reserved for account-recovery and migration tools. Should be an extremely short list, ideally empty except for tools you deliberately set up.
How to revoke access
On the permissions page, click any app you no longer use or don’t recognize, then click Remove Access. This immediately invalidates that app’s OAuth tokens — it can no longer read your data, and if it needs access again, you’ll have to explicitly re-authorize it.
Removing access doesn’t delete any data the app already downloaded or stored on its own servers before you revoked it — it only stops future access. If an app had access to sensitive data and you’re not sure what it did with it, that’s a separate conversation with that app’s own privacy policy, not something Google’s revoke button can undo.
Don’t stop at apps — check devices too
A related but separate page, myaccount.google.com/device-activity, shows every device currently signed into your Google account: phones, laptops, smart TVs, anything. If you see a device you don’t recognize, or one you sold/gave away years ago that’s still listed, click it and select Sign out. This is the single most useful check after you suspect — even vaguely — that your password may have leaked, because it immediately kicks out any session an attacker might be holding, independent of whether you’ve changed your password yet.
A five-minute routine worth repeating
- Open myaccount.google.com/permissions, scan the list, and remove anything you don’t actively use or don’t recognize.
- Open myaccount.google.com/device-activity and sign out anything unfamiliar.
- If you’re not sure whether a password you use elsewhere has already leaked, run it through a password breach checker — it checks against real breach data without ever sending your actual password anywhere.
None of this requires installing anything or trusting a third party with your account — it’s all built into Google’s own settings, and it takes less time than reading this article did.