Airia · OAuth Scopes

Airia OAuth Scopes

OAuth 2.0 probed

Airia publishes 15 OAuth 2.0 scopes. Scopes are the fine-grained permissions an application requests at authorization time to act against the Airia API on a user’s behalf.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanyEnterprise AIAI AgentsAI GovernanceAI SecurityMCPMCP GatewayAgent OrchestrationLLM GatewayAI DiscoveryRed TeamingGuardrailsKnowledge RetrievalRAGAgent-Native
Scopes: 15 Flows: Method: probed

Scopes (15)

ScopeDescriptionFlows
mcp.read Read access to the MCP Gateway — list and inspect the tools, resources and skills a gateway exposes.
mcp.write Invoke tools through the MCP Gateway.
openid Standard OIDC scope; issues an ID token.
profile Standard OIDC profile claims.
email Standard OIDC email claim.
address Standard OIDC address claim.
phone Standard OIDC phone claim.
roles Keycloak realm/client roles claim — the roles that decide what a token can do inside Airia.
groups Keycloak group membership claim.
active_organization The tenant/organization the token is currently acting within.
enterprise Airia enterprise client scope.
basic Keycloak basic scope (sub, auth_time).
acr Authentication context class reference.
web-origins Keycloak CORS origins scope.
microprofile-jwt MicroProfile JWT claims (upn, groups).

Source

OAuth Scopes

Raw ↑
generated: '2026-09-19'
method: probed
source: https://mcp-gateway.airia.ai/.well-known/oauth-protected-resource
docs: https://airia.ai/docs/settings/developer/api-keys
description: >-
  OAuth scopes Airia publishes. These come from the MCP Gateway's RFC 9728 protected-resource
  metadata and the Keycloak realm's OpenID discovery document, both fetched anonymously — not from
  the REST OpenAPI, which declares only apiKey schemes (X-API-Key and a session cookie) and no
  oauth2 securityScheme at all. So the platform REST API is not scope-governed; the MCP Gateway is.
  Access to the REST API is instead governed by ROLES bound to a key, which are resolved live on
  every request; the role/permission vocabulary is documented in the console's permissions reference
  and is not published anonymously.
authorization_servers:
- issuer: https://mcp-gateway.airia.ai
  metadata: well-known/airia-mcp-gateway-oauth-authorization-server.json
  authorization_endpoint: https://identity.airia.ai/auth/realms/airia/protocol/openid-connect/auth
  token_endpoint: https://identity.airia.ai/auth/realms/airia/protocol/openid-connect/token
  registration_endpoint: https://mcp-gateway.airia.ai/.well-known/oauth-authorization-server/v1/register
  pkce: S256
- issuer: https://identity.airia.ai/auth/realms/airia
  metadata: well-known/airia-identity-openid-configuration.json
  registration_endpoint: https://identity.airia.ai/auth/realms/airia/clients-registrations/openid-connect
resources:
- resource: https://mcp-gateway.airia.ai
  metadata: well-known/airia-mcp-gateway-oauth-protected-resource.json
  bearer_methods_supported:
  - header
- resource: https://prodaus.mcp-gateway.airia.ai
  metadata: well-known/airia-prodaus-mcp-gateway-oauth-protected-resource.json
  note: Australian regional gateway; identical scope set.
scopes:
- name: mcp.read
  description: Read access to the MCP Gateway — list and inspect the tools, resources and skills a gateway exposes.
  source: https://mcp-gateway.airia.ai/.well-known/oauth-protected-resource
- name: mcp.write
  description: Invoke tools through the MCP Gateway.
  source: https://mcp-gateway.airia.ai/.well-known/oauth-protected-resource
- name: openid
  description: Standard OIDC scope; issues an ID token.
- name: profile
  description: Standard OIDC profile claims.
- name: email
  description: Standard OIDC email claim.
- name: address
  description: Standard OIDC address claim.
- name: phone
  description: Standard OIDC phone claim.
- name: roles
  description: Keycloak realm/client roles claim — the roles that decide what a token can do inside Airia.
- name: groups
  description: Keycloak group membership claim.
- name: active_organization
  description: The tenant/organization the token is currently acting within.
- name: enterprise
  description: Airia enterprise client scope.
- name: basic
  description: Keycloak basic scope (sub, auth_time).
- name: acr
  description: Authentication context class reference.
- name: web-origins
  description: Keycloak CORS origins scope.
- name: microprofile-jwt
  description: MicroProfile JWT claims (upn, groups).
identity_realm_only_scopes:
- name: airia-knowledge
  description: >-
    Present on the identity.airia.ai realm but NOT in the MCP Gateway's advertised scope set —
    knowledge/retrieval access issued to first-party surfaces.
  source: https://identity.airia.ai/auth/realms/airia/.well-known/openid-configuration
- name: service_account
  description: Client-credentials service-account scope on the realm, not offered through the gateway.
  source: https://identity.airia.ai/auth/realms/airia/.well-known/openid-configuration
rest_api_authorization:
  model: roles-on-api-key
  note: >-
    Not OAuth scopes. A key is created with either no roles (a personal access token carrying the
    creating user's permissions) or one or more roles (a service account). Permissions are resolved
    fresh on every request from those roles, Platform Admin can never be assigned to a key, and a
    key cannot be issued with more permission than its creator holds at creation time.
  docs: https://airia.ai/docs/settings/developer/api-keys

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/airia-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.