We built this after an incident

A note-taking app kept read access to an executive mailbox for fourteen months after the person who approved it left. Nobody had done anything wrong. There was simply no list.

The list is the product

OAuth consent moved authorisation out of IT and into the hands of every employee. That was the right trade for adoption, and it left security teams without an inventory of what their company had agreed to.

We refuse to rank vendors. There is no OAuthRadar blocklist, no vendor we quietly penalise, no partnership that moves a score. A grant is scored on its scopes, its usage and the vendor's published posture. We publish the weights, so a score you disagree with is an argument you can win.

We also refuse to hold what we do not need. Tokens are encrypted in a separate keyspace, never displayed in full, and deleted within a minute of a disconnect. The product ships an export before it ships a chart, because most of us have been on the receiving end of a third-party access review.

Founded
2024, in Lyon
Team
Eleven people, Lyon and Montreal
Backing
Seed round, 2025

Come and disagree with our weights

Thirty minutes, on your own tenant, with the scoring model open in front of you.