Gymkhana Profiles OAuth API
An OAuth 2.0 (RFC 6749) identity and profile API operated by the IIT Bombay Students' Gymkhana, with ten separately-consented scopes covering SSO id, name, picture, sex, LDAP username and e-mail, phone, campus address, student record (roll number, department, course, joining and graduation year), alternate e-mails, and permission to send mail on the user's behalf. It is the only place in IIT Bombay's public footprint where student-record fields are exposed under explicit user consent. Access is restricted by policy: the documentation states that Profiles is intended only for applications running on Gymkhana server infrastructure and that others may be deleted and blocked without notice. No RFC 8414 authorization-server metadata is published.