# We could use more scopes

**URL:** <https://community.homey.app/t/we-could-use-more-scopes/152593>\
**Category:** Developers\
**Created:** [March 17, 2026, 9:07am UTC](https://community.homey.app/t/we-could-use-more-scopes/152593 "2026-03-17T09:07:11Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![smarthomesven](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/smarthomesven/32/79712_2.png) [@smarthomesven](https://community.homey.app/u/smarthomesven)\
**Post date:** [March 17, 2026, 9:38am UTC](https://community.homey.app/t/we-could-use-more-scopes/152593/4 "2026-03-17T09:38:02Z")

</div>

> [@Tim\_Broddin](#):
>
> you could easily create a small botnet if tokens leak

Did you know Athom doesn’t review the code of community apps? There’s a hidden route (that’s not visible to regular users) in the Homey Developer Tools, which is the page they use for reviewing apps. I couldn’t see anything other than the app manifest there. So I think if someone would really have bad intentions, they would just build an app for something many users asked for. That would be far more effective for attackers than trying to get users to add a malicious OAuth app

Edit: something similar has actually happened before (while that was about spamming the timeline):

> [@New community store](https://community.homey.app/t/new-community-store/122980/50):
>
> Let me clarify what happened, before this goes out of hand and everyone keeps speculating slight_smile@Menno_van_Hout requested that his apps be removed from the Homey App Store. While still in talks with employees from Athom, who were very understanding, but also noticed that his main reason was to force people to use his alternative app store, Athom offered to find alternative developers to take over his apps, as we usually do. Menno did not seem to have an interest in that. Then Menno pu…

---

_[View the full topic](https://community.homey.app/t/we-could-use-more-scopes/152593)._
