4.screen · OAuth Scopes

4.screen OAuth Scopes

OAuth 2.0 probed

4.screen uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanyAdvertisingAdTechAutomotiveMobilityConnected VehiclesIn-Car CommerceLocationNavigationMarketingGermany
Scopes: 0 Flows: Method: probed

Scopes (0)

4.screen implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.

Source

OAuth Scopes

4screen-scopes.yml Raw ↑
generated: '2026-09-05'
method: probed
source: https://api.4screen.com/auth/realms/fourscreen/.well-known/openid-configuration
docs: null
name: 4.screen OAuth 2.0 scopes
description: >-
  The complete scopes_supported list advertised by 4.screen's Keycloak realm.
  Two of these are first-party business scopes that map directly onto 4.screen's
  two-sided marketplace — the demand side (advertisers and businesses buying
  in-car placements) and the supply side (automakers and mobility service
  providers serving them). The rest are Keycloak/OIDC standard scopes.
  NOTE: which scope each API operation requires is NOT published — there is no
  public API reference — so the descriptions of the two first-party scopes below
  are marked inferred and must not be read as documented behaviour.

issuer: https://api.4screen.com/auth/realms/fourscreen
authorization_endpoint: https://api.4screen.com/auth/realms/fourscreen/protocol/openid-connect/auth
token_endpoint: https://api.4screen.com/auth/realms/fourscreen/protocol/openid-connect/token
scope_count: 14
first_party_scope_count: 3

scopes:
  - name: demand-client-scope
    category: first-party
    documented: false
    description: >-
      INFERRED, not documented. 4.screen's own naming for the demand side of its
      marketplace — the businesses, brands and agencies that buy Branded Pins,
      Sponsored Search, Recommendations and Detail Screen placements. This is the
      scope the 4.screen customer portal client would carry.
  - name: supply-operations-client-scope
    category: first-party
    documented: false
    description: >-
      INFERRED, not documented. 4.screen's own naming for the supply side — the
      automaker/OEM and mobility-service-provider integrations that render
      4.screen content inside an infotainment system, plus the operational
      tooling around them.
  - name: service_account
    category: first-party
    documented: false
    description: >-
      Keycloak service-account scope, used by client_credentials machine clients.
      Present in the realm's scopes_supported list.

  - name: openid
    category: oidc-standard
    documented: true
    description: Required to request an ID token (OpenID Connect Core 1.0).
  - name: profile
    category: oidc-standard
    documented: true
    description: name, given_name, family_name, preferred_username claims.
  - name: email
    category: oidc-standard
    documented: true
    description: email claim.
  - name: phone
    category: oidc-standard
    documented: true
    description: phone_number claims.
  - name: address
    category: oidc-standard
    documented: true
    description: address claim.
  - name: offline_access
    category: oidc-standard
    documented: true
    description: Issues a refresh token usable while the user is offline.
  - name: acr
    category: keycloak-default
    documented: true
    description: Authentication Context Class Reference claim (acr_values 0 and 1 advertised).
  - name: basic
    category: keycloak-default
    documented: true
    description: Keycloak default client scope carrying sub and auth_time.
  - name: roles
    category: keycloak-default
    documented: true
    description: Realm and client role mappings in the token.
  - name: web-origins
    category: keycloak-default
    documented: true
    description: CORS allowed-origins mapper.
  - name: microprofile-jwt
    category: keycloak-default
    documented: true
    description: Eclipse MicroProfile JWT claims (upn, groups).

gaps:
  - >-
    No scopes/permissions reference page exists on any public 4.screen surface.
    docs: is null for that reason, not because the search was skipped —
    docs.4screen.com and developer.4screen.com do not resolve in DNS, and
    4screen.com has no developer section in its sitemap.
  - >-
    Operation-to-scope mapping is unavailable because api.4screen.com returns
    401 on every springdoc/OpenAPI path and on /graphql.

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/4screen-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.