American Financial Group · OAuth Scopes
American Financial Group OAuth Scopes
OAuth 2.0
searched
American Financial Group uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
InsuranceProperty CasualtySpecialty InsuranceAnnuitiesFinancial-ServicesCommercial InsuranceFortune 500
Scopes: 0
Flows:
Method: searched
Scopes (0)
American Financial Group implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.
Great American secures every Carrier Services API with OAuth 2.0 client_credentials but publishes no named scope vocabulary. Authorization is carried instead by `api_product_list_json` on the token response — an array of granted API product identifiers (documented example: ["issuance-dev","rating-dev"]) — and is further narrowed per consumer at runtime: GET /api/endpoints returns only the endpoints that client is entitled to call, and a call to an unentitled endpoint returns 501 Not Implemented. The published scope list is therefore genuinely empty, not merely unfound; the entitlement surface is per-client and must be read from the live /api/endpoints response.
Great American secures every Carrier Services API with OAuth 2.0 client_credentials but publishes no named scope vocabulary. Authorization is carried instead by `api_product_list_json` on the token response — an array of granted API product identifiers (documented example: ["issuance-dev","rating-dev"]) — and is further narrowed per consumer at runtime: GET /api/endpoints returns only the endpoints that client is entitled to call, and a call to an unentitled endpoint returns 501 Not Implemented. The published scope list is therefore genuinely empty, not merely unfound; the entitlement surface is per-client and must be read from the live /api/endpoints response.
📄 Provider scope reference: https://api-documentation.gaig.com/policy/index.html
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.