How To De-Authorize And Manage Account Access In EVE Online
Managing third-party account authorizations in EVE Online is a critical security procedure that involves revoking OAuth tokens through the official EVE Online account management portal to prevent unauthorized API access to your character data. This process ensures that inactive, compromised, or untrusted external applications, such as killboard trackers or market tools, no longer hold valid authentication headers to query your private game information.
Security Prerequisites and Access Requirements
Maintaining a secure EVE Online account requires a disciplined approach to managing the tokens issued to third-party services. EVE Online utilizes the OAuth 2.0 protocol, which allows external applications to access specific scopes of your account data—such as wallet history, location, or mail—without needing your actual login credentials. Before initiating a cleanup of your authorized applications, ensure you meet the following baseline requirements to maintain account integrity.
- Essential Requirements:
- Access to the official EVE Online Account Management website via a secure browser session.
- Knowledge of your primary credentials, including your email address and password for the associated SSO account.
- Active Two-Factor Authentication (2FA) enabled on your account to prevent unauthorized access during the management session.
- A list of currently used tools or applications you rely on to identify which tokens should be retained versus those that are obsolete.
- Estimated time: 5 to 10 minutes for a full security audit and token revocation.
- Budget: Zero cost; this is a standard security feature provided by CCP Games.
Step-by-Step Procedure for Revoking Third-Party OAuth Tokens
The process of de-authorizing applications is managed entirely through the CCP account portal. Follow these technical steps to systematically clean your access logs and secure your character data.
Step 1: Navigating to the Authorized Applications Dashboard
Log in to the official EVE Online website using your account credentials. Once the dashboard loads, navigate to the Account menu located in the top-right corner of the interface. Select the Services or Settings tab to locate the section specifically labeled Authorized Applications. This screen acts as the master registry for every third-party service that has been granted permission to access your EVE Online data through the Single Sign-On (SSO) system.
Step 2: Evaluating Existing Application Scopes
Review the list displayed on the screen. Each entry will typically list the name of the application, the date the access was granted, and the specific scopes—or permissions—the application was authorized to access.
Warning: Be highly skeptical of any application entry that you do not recognize or that claims to require access to your full account scope without a clear functional reason. If you see an application you no longer use, such as a defunct killboard or an old industry planning tool, it should be removed immediately.
Step 3: Executing the Revocation Protocol
To revoke access, locate the specific application in the list and click the Revoke or Remove button associated with that entry. Once confirmed, the EVE Online authentication server invalidates the refresh tokens associated with that application. This action is instantaneous; the external tool will no longer be able to pull data from the EVE ESI (EVE Swagger Interface) using the previously authorized token.
Step 4: Verification and Re-Authentication
After removing the unnecessary applications, log out of the account management portal and clear your browser cache if you suspect the machine may be shared. If you find that a tool you legitimately use has stopped functioning, navigate back to that specific tool’s website and re-authorize it. This effectively creates a new, fresh token, which is a good practice if you suspect your previous session data was intercepted.
OIDC Authentication | Cloudreve
Technical Comparison of Access Scope and Security Risk
The following table outlines the common types of permissions granted to third-party services and the relative risk associated with each. When reviewing your authorizations, consider whether the service truly requires the level of access it currently holds.
| Scope Category | Data Accessibility Level | Security Risk Level | Recommended Action |
|---|---|---|---|
| Public Data | Character name, corp, alliance | Negligible | Maintain if useful |
| Market/Wallet | Transaction history, wallet balance | Moderate | Remove if inactive |
| Location/Ship | Real-time ship data, solar system | High | Monitor strictly |
| Mail/Contacts | Private communication, buddy list | High | Remove if unused |
| Roles/Assets | Station contents, corp roles | Critical | Audit frequently |
Common Security Failures and Remediation Strategies
Even with diligent management, users often encounter issues regarding API synchronization or account access. Address these common failures to ensure your security posture remains robust.
- Issue: Application access remains after revocation.
- Root Cause: Some third-party tools cache data locally even after the API token is revoked, or they use multiple separate character tokens.
- Actionable Fix: Clear the application's local cache or, in the case of desktop software, perform a clean reinstall of the tool to ensure no stale data remains in its internal database.
- Issue: Unable to authorize a legitimate third-party tool.
- Root Cause: Expired browser cookies or a conflict with an active VPN session preventing the EVE SSO redirect.
- Actionable Fix: Disable your VPN temporarily, clear browser cookies for the EVE Online domain, and attempt the authorization process again in an incognito or private browsing window.
- Issue: High-frequency API errors (Error 403 Forbidden) appearing in logs.
- Root Cause: The ESI token has expired or was revoked by the security protocol, but the app is still attempting to poll the server.
- Actionable Fix: Delete the existing configuration within the third-party application and perform a fresh login via the SSO link to generate a valid, active token.
Frequently Asked Questions
Does revoking an application delete my character or assets?
No. Revoking an application only severs the technical connection between your EVE Online account and that specific third-party service. It does not affect your character, your inventory, your ISK balance, or any data stored on CCP Games' servers.
How often should I audit my authorized applications?
It is a security best practice to perform an audit of your authorized applications at least once every six months or immediately after you stop using a specific third-party website or tool. Frequent auditing limits the window of opportunity for an attacker if a third-party service suffers a data breach.
Can a third-party app delete items or steal my ISK?
Applications that hold "write" permissions or access to your inventory and wallet can initiate trades or moves depending on the scopes you granted. If you have granted such permissions to a tool you no longer trust, revoke the access immediately to prevent unauthorized asset movement.
Will revoking an application break my killboard profile?
Revoking access will stop the application from pulling new data. Existing data already published to a third-party killboard or profile site will usually remain visible on that site, but the site will no longer be able to update your history until you re-authorize it.
Take Control of Your Security Today
Securing your EVE Online profile is an ongoing responsibility that protects your progress and hard-earned assets from evolving digital threats. Audit your authorized application list today to ensure only trusted services have access to your character's vital information.