RP
RevenueProven
All Help Articles

What permissions and scopes does each integration need?

LinkedIn needs ad analytics read and campaign management scopes. HubSpot needs Companies and Deals read. Salesforce needs API access and Account and Opportunity read permissions.

Revenue Proven requests the minimum OAuth scopes needed to pull attribution-relevant data. No write scopes are requested for your CRM integrations. Below is a breakdown of what each integration needs and why.

LinkedIn Ads scopes

  • r_ads_reporting: read ad analytics and engagement metrics (required for attribution)
  • rw_ads: read campaign data including campaign IDs and names
  • r_organization_social: read organization profile data for company name resolution
  • rw_media_plans: required only if you use the Media Planning sync feature
  • r_ad_library: required only for Competitor Intelligence (needs LinkedIn approval)

HubSpot scopes

  • crm.objects.companies.read: read company records including domain and name
  • crm.objects.deals.read: read deal amounts, close dates, and pipeline stages
  • crm.schemas.deals.read: read pipeline stage definitions and labels

Salesforce permissions

  • API Enabled: profile-level permission required for any API access
  • Account read: read company name, website, and associated fields
  • Opportunity read: read deal amount, stage, close date, and account association
  • Opportunity Stage (OpportunityStage) read: read stage labels and win probability

Revenue Proven never requests permissions to create, update, or delete records in any connected system. OAuth tokens are stored encrypted in the database and the raw token is never logged or exposed in the UI.