Aedifion OAuth Scopes
Aedifion publishes 13 OAuth 2.0 scopes via the implicit, authorizationCode, password, and clientCredentials flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the Aedifion API on a user’s behalf.
Tokens are issued from https://auth.aedifion.io/realms/aedifion/protocol/openid-connect/token.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
OAuth endpoints
https://auth.aedifion.io/realms/aedifion/protocol/openid-connect/auth
https://auth.aedifion.io/realms/aedifion/protocol/openid-connect/token
implicitauthorizationCodepasswordclientCredentials
Scopes (13)
| Scope | Description | Flows |
|---|---|---|
| openid | Use OpenID Connect (required). The only scope the OpenAPI itself declares. | implicit, authorizationCode |
| profile | Basic profile claims (name, preferred_username, locale). | |
| Email address and verification status. | ||
| address | Address claim. | |
| phone | Phone number claim. | |
| roles | Realm and client role mappings, which carry the platform's RBAC assignments. | |
| api | Access to the aedifion HTTP API as a resource. | |
| offline_access | Issue a refresh token usable while the user is offline. | |
| service_account | Client-credentials service account access. | |
| basic | Keycloak basic scope (sub, auth_time claims). | |
| acr | Authentication context class reference claim. | |
| microprofile-jwt | MicroProfile JWT claims (upn, groups). | |
| web-origins | CORS allowed origins claim. |
📄 Provider scope reference: https://docs.aedifion.io/en/developers/http-api/guides-and-tutorials/authentication/
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.