Third-party & OAuth apps security checks across 5 apps
OAuth grants, marketplace apps, integrations, plugins and automations with standing access to company data — the SaaS-to-SaaS supply chain.
Why it matters
OAuth grants, marketplace apps and automations hold standing access to company data long after the person who approved them stopped using them. This SaaS-to-SaaS supply chain is exactly what DORA's Register of Information and NIS2's supply-chain duties now ask you to inventory and justify.
Browse by app
Highest-severity checks
The 8 most severe Third-party & OAuth apps checks across all 5 apps — each links to the connector page where the setting, its remediation and its framework mapping are documented.
- Application Risky Grant Type — PingOne severity: high
- Application Risky Grant Type — Auth0 severity: high
- Bot With Admin — Discord severity: high
- Integration Using Basic Auth — ServiceNow severity: high
- OAuth App Insecure Redirect — ServiceNow severity: high
- Public Client With Confidential Grant — Auth0 severity: high
- Application Public Client Without Auth — PingOne severity: medium
- Application Wildcard Redirect URI — PingOne severity: medium
Where to start
Connect Discord first — it carries the most Third-party & OAuth apps checks in the catalog(setup guide, read-only access). A first scan takes about 15 minutes and reports every failing check on this page with its remediation steps.