Authorized Apps
Last updated Aug 15, 2026
Authorized Apps
When you use Swaymoon Account to sign in to a third-party app (an App or a website), the app asks to access some information or capabilities in your account. You can review the request on the authorization page and decide whether to continue.
What happens during authorization
- The app redirects to Swaymoon Account.
- If you are not signed in yet, sign in first (see Sign In).
- You reach the Request access page, which shows:
- The app name and icon (if any)
- Your account identity
- A permission list: each item is marked Required or Optional
- If the account has a linked email, you can also choose whether to use Hide My Email (hide your real email from this app; mail is forwarded through the relay)
- If the developer has registered one, you can open this app’s Privacy Policy link. If the link points to a site outside Swaymoon, you will be warned before opening it that the domain is not controlled by Swaymoon
- Permissions are grouped as Required and Optional. Check the optional items you are willing to grant (required items cannot be unchecked).
- If this request includes email permission and the account has a linked email: next to the email permission, a dropdown lets you choose Hide My Email (default) or Real email (also available when the primary sign-in method is a phone number but an email is already linked). The option does not appear if email was not requested, or if no email is linked. Swaymoon first-party apps (such as the Developer portal) do not offer Hide My Email; they use your real email.
- If the app needs email permission and your account has no linked email yet: you are first guided to link and verify an email, then returned to authorization (you can also uncheck optional email permission and continue, if that item is not required).
- Tap Continue to finish authorization, or Cancel to refuse.
After authorization, the app can read information within the scope you agreed to, until you stop using the app or revoke the related consent (subject to what the product actually supports and applicable rules).
How to choose permissions
- Check only the permissions the app’s current features actually need. Profile permissions (display name, nickname, avatar, bio, gender, birthday, region, username, and so on) are listed separately, can be unchecked individually, and are generally not marked required (except for Swaymoon first-party apps).
- If an app asks for sensitive permissions unrelated to its features, uncheck the matching optional items, or cancel authorization entirely.
- For email: the app may mark email as required or optional; if it is optional, you can uncheck it. When you choose Hide My Email, the app only receives a relay address, not your real email (see Hide My Email).
View and manage authorizations
After you sign in to Swaymoon Account, open Privacy → App authorizations:
- The list shows apps that have signed in through Swaymoon Account, and the time of first authorization.
- Open an app’s details to see authorization time, network and device environment, and the permissions granted at that time. If the developer has registered one, you can also open this app’s Privacy Policy link (if it points to a site outside Swaymoon, you will be warned before leaving: that domain is not controlled by Swaymoon, and its content is not managed by Swaymoon).
- The Activity timeline on the details page lists, in time order: first authorization, sign-in with this app, updated authorization, revoked authorization, re-authorization, and similar events (repeat sign-ins to the same app in a short period are merged so the list does not flood).
- You can Revoke an authorization that is still active. After revoke, the app cannot sign in with Swaymoon Account until you authorize it again.
- You can also choose Revoke and request data deletion: at the same time as revoke, Swaymoon Account emails the developer and sends a signed request to their configured data-deletion callback URL, asking them to delete saved data related to you. Final deletion depends on the developer.
- After revoke, the record is kept and marked as revoked, so you can review history.
How an app stores and uses data after it is authorized is governed by that app’s privacy policy. If the developer registered a privacy policy link on the identifier, you can view it on the consent page or in authorization details; opening it leaves the Swaymoon site. If you no longer trust an app, besides managing authorization in Swaymoon Account, you should also check account linking and deletion options inside that app.
Notes
- After you revoke or stop using an app, how the app deletes data it already obtained may still need to follow its own rules and applicable law, in addition to using Revoke and request data deletion.
- Do not enter your Swaymoon Account password on unfamiliar websites. Legitimate integrations should redirect to official domains such as
passport.swaymoon.comto complete sign-in and authorization.
How developers integrate Swaymoon Account: turn on Developer Mode at the top right of the docs site (tap again to switch to Developer only), then read Swaymoon Developer → Guides → Identifiers (start with Register and Configure and Integration Overview), and register an identifier at develop.swaymoon.com. Before you become a developer, Swaymoon Account must already have a linked email.