Skip to main content
A company admin grants scopes on the OAuth consent screen. Your token can only do what its granted scopes allow; an endpoint that needs a scope you don’t have returns 403 missing_scope.

Available now

Notes

  • email is never returned without users:read.email, and even then only when the person’s email visibility allows it. A withheld email is indistinguishable from no match on GET /v1/users/lookup — both return 404 user_not_found.
  • Phone numbers are never returned by any scope.
  • There’s no scope for reading a bot’s own messages back beyond what POST /v1/messages and PATCH /v1/messages/{id} already return — message history read is conversations:history, above.