401GO · OAuth Scopes

401GO OAuth Scopes

OAuth 2.0 searched

401GO publishes 12 OAuth 2.0 scopes via the authorizationCode and clientCredentials flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the 401GO API on a user’s behalf.

Tokens are issued from https://app.401go.com/api/o/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanyRetirement401kFinancial ServicesFintechPayrollHuman ResourcesBenefitsInvestmentsWealth Management
Scopes: 12 Flows: authorizationCode, clientCredentials Method: searched

OAuth endpoints

Authorization URL
https://app.401go.com/api/o/authorize
Token URL
https://app.401go.com/api/o/token
Flows
authorizationCodeclientCredentials

Scopes (12)

ScopeDescriptionFlows
openid OpenID Connect SSO. By default grants access to employee (participant) identity only; pair with company:read to use SSO for a company admin. authorizationCode
participant:read Read participant (employee) data — census record, deferrals, totals, portfolio, beneficiaries, loans, disbursements, rollovers, notifications, documents. authorizationCode, clientCredentials
participant:write Create and update participant data — participant records, deferral elections, beneficiaries, portfolio allocations, loan and disbursement and rollover requests. authorizationCode, clientCredentials
participant:billing Access participant billing-related data. authorizationCode, clientCredentials
company:read Read company data — company list, plan provisions, employer match formulas, investment options, company affiliates, participant census. authorizationCode, clientCredentials
company:write Write company-scoped data, including payroll submission. authorizationCode, clientCredentials
plan:read Read 401(k) plan configuration. authorizationCode, clientCredentials
plan:write Create and update 401(k) plans via the plan-setup endpoints. authorizationCode, clientCredentials
affiliate_firm:read Read affiliate firm data — affiliates, fund lineups, pooled plans, pricing tiers. authorizationCode, clientCredentials
affiliate_firm:write Write affiliate firm data. authorizationCode, clientCredentials
affiliate:read Read individual affiliate (advisor) data, including pricing tiers. authorizationCode, clientCredentials
affiliate:write Write individual affiliate (advisor) data. authorizationCode, clientCredentials

Source

OAuth Scopes

Raw ↑
generated: '2026-08-02'
method: searched
source: https://app.401go.com/api/o/.well-known/openid-configuration
docs: https://developer.401go.com/docs/authentication
note: >-
  The published OpenAPI declares its OAuth surface as an http/bearer scheme rather than an
  oauth2 scheme, so the mechanical derive pass finds no scopes. The real authorization server
  metadata is published at app.401go.com/api/o/.well-known/openid-configuration, and the
  scopes below are its verbatim scopes_supported list. 401GO layers a second, non-OAuth
  authorization control on top: a per-client endpoint + HTTP-method allow list negotiated at
  onboarding, documented at
  https://developer.401go.com/docs/api-endpoint-and-method-access. Holding a scope is
  therefore necessary but not sufficient — an unlisted endpoint/method returns 403.
issuer: https://app.401go.com/api/o
schemes:
- name: oauth2
  source: https://app.401go.com/api/o/.well-known/openid-configuration
  flows:
  - flow: authorizationCode
    authorizationUrl: https://app.401go.com/api/o/authorize
    tokenUrl: https://app.401go.com/api/o/token
    pkce: true
    code_challenge_methods: [plain, S256]
  - flow: clientCredentials
    tokenUrl: https://app.401go.com/api/o/token
    docs: https://developer.401go.com/docs/client-credentials-flow
    note: restricted to approved partners; credentials distributed by secure email
  token_endpoint_auth_methods: [client_secret_post, client_secret_basic]
  access_token_lifetime: 3600
  refresh_token_lifetime: 2592000
scopes:
- scope: openid
  description: OpenID Connect SSO. By default grants access to employee (participant)
    identity only; pair with company:read to use SSO for a company admin.
  flows: [authorizationCode]
  sources: [openid-configuration, docs]
- scope: participant:read
  description: Read participant (employee) data — census record, deferrals, totals,
    portfolio, beneficiaries, loans, disbursements, rollovers, notifications, documents.
  flows: [authorizationCode, clientCredentials]
  sources: [openid-configuration, docs]
- scope: participant:write
  description: Create and update participant data — participant records, deferral elections,
    beneficiaries, portfolio allocations, loan and disbursement and rollover requests.
  flows: [authorizationCode, clientCredentials]
  sources: [openid-configuration, docs]
- scope: participant:billing
  description: Access participant billing-related data.
  flows: [authorizationCode, clientCredentials]
  sources: [openid-configuration]
- scope: company:read
  description: Read company data — company list, plan provisions, employer match formulas,
    investment options, company affiliates, participant census.
  flows: [authorizationCode, clientCredentials]
  sources: [openid-configuration, docs]
- scope: company:write
  description: Write company-scoped data, including payroll submission.
  flows: [authorizationCode, clientCredentials]
  sources: [openid-configuration]
- scope: plan:read
  description: Read 401(k) plan configuration.
  flows: [authorizationCode, clientCredentials]
  sources: [openid-configuration]
- scope: plan:write
  description: Create and update 401(k) plans via the plan-setup endpoints.
  flows: [authorizationCode, clientCredentials]
  sources: [openid-configuration]
- scope: affiliate_firm:read
  description: Read affiliate firm data — affiliates, fund lineups, pooled plans, pricing tiers.
  flows: [authorizationCode, clientCredentials]
  sources: [openid-configuration]
- scope: affiliate_firm:write
  description: Write affiliate firm data.
  flows: [authorizationCode, clientCredentials]
  sources: [openid-configuration]
- scope: affiliate:read
  description: Read individual affiliate (advisor) data, including pricing tiers.
  flows: [authorizationCode, clientCredentials]
  sources: [openid-configuration]
- scope: affiliate:write
  description: Write individual affiliate (advisor) data.
  flows: [authorizationCode, clientCredentials]
  sources: [openid-configuration]
x-evidence:
  fetched: '2026-08-02'
  url: https://app.401go.com/api/o/.well-known/openid-configuration
  http_status: 200
  scopes_found: 12