Chrome extensions often request access to your Google Account through OAuth — to your mail, contacts, Drive files, or calendar. The catch: even after you remove the extension from the browser, the granted permission stays active. You can revoke it manually, and it's worth doing regularly — especially if you use the same account to pay for overseas services and store payment-related data.
Step 1. Open your Google Account permissions
Go to myaccount.google.com/permissions — the "Third-party apps with account access" section. This is where every service and extension that has ever received OAuth access is listed. The page works the same on Windows and Mac, since the settings live with your account, not the device.
Step 2. Find the extension in the list
Scroll through the list and locate the Chrome extension whose access you want to revoke. Click it to open a card showing exactly what it can do — read your mail, manage files, access contacts, and so on.
Step 3. Revoke access
In the extension's card, click the option to remove access and confirm. From that moment the OAuth token stops working: the extension can no longer reach your account data until you authorize it again.
Step 4. Remove the extension from the browser
Revoking access in your Google Account doesn't uninstall the extension from Chrome. To remove it completely, open chrome://extensions in the browser, find the extension, and click "Remove." That closes the loop from both sides: the permission is revoked and the extension's code no longer runs.
What happens after revocation
- The extension loses access to your account data immediately.
- If you reinstall and sign in again, you'll have to go through the permission flow once more.
- Some extensions may stop working properly — that's expected, since their account access is cut off.
- Any data the extension already stored on its side stays with it — revoking OAuth doesn't delete information it has already exported.
Why this matters for payment security
The more third-party extensions have access to your Google Account, the wider your attack surface. If you use that account to sign into overseas services, subscriptions tied to it, or an inbox full of receipts and payment notifications, extra permissions mean extra risk. A regular audit of your OAuth grants is a simple habit that lowers the odds of a leak or unwanted account use.
FAQ
Does revoking access uninstall the extension from Chrome?
No. These are two separate actions: the permission is revoked in your Google Account, while the extension itself is removed on the chrome://extensions page.
Do I need to do this differently on Windows and Mac?
No. Permission settings are stored with your Google Account, not on the device, so the steps are identical.
What if I reinstall the extension later?
On the first sign-in it will ask for access again, and you can decide whether to grant it.
Can I revoke access to only part of my data?
Usually not — permissions are granted as a bundle. If you only want one type of access, it's simpler to deny the extension entirely.
This article is for informational purposes only and is not financial advice.
A virtual card in 2 minutes
Pay for subscriptions, AI tools, travel, and international stores. Top up via USDT-TRC20 with no acquiring fees.