American International Group (AIG) OAuth Scopes

OAuth 2.0 probed

American International Group (AIG) uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

InsuranceProperty CasualtyCyber InsuranceCommercial InsuranceGlobal InsuranceFinancial-ServicesReinsuranceFortune 500
Scopes: 0 Flows: Method: probed

Scopes (0)

American International Group (AIG) implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.

Source

OAuth Scopes

american-international-scopes.yml Raw ↑
generated: '2026-09-02'
method: probed
source: >-
  https://auth1.customerpltfm.aig.com/oauth2/aus1aaqj1zvwVDL2n5d7/.well-known/oauth-authorization-server
  (HTTP 200, fetched anonymously 2026-09-02)
provider: American International Group (AIG)
providerId: american-international
docs: null
docs_note: >-
  AIG publishes no scopes or permissions reference page. Every scope below is read verbatim from
  the scopes_supported array of AIG's own anonymously-served authorization-server metadata; the
  descriptions are the standard OIDC/Okta meanings, and the two AIG-specific scopes are recorded
  with their meaning marked unknown rather than guessed.
authorization_server: https://auth1.customerpltfm.aig.com/oauth2/aus1aaqj1zvwVDL2n5d7
scope_count: 13
scopes:
  - name: openid
    description: OpenID Connect authentication; required to receive an ID token.
    standard: true
  - name: profile
    description: Basic profile claims (name, preferred_username, locale, updated_at).
    standard: true
  - name: email
    description: The email and email_verified claims.
    standard: true
  - name: address
    description: The address claim.
    standard: true
  - name: phone
    description: The phone_number and phone_number_verified claims.
    standard: true
  - name: offline_access
    description: Issues a refresh token so the client can renew access without user interaction.
    standard: true
  - name: device_sso
    description: Okta device single-sign-on; binds the token to a registered device.
    standard: false
    vendor: Okta
  - name: interclient_access
    description: >-
      Okta token-exchange scope permitting one client's token to be exchanged for another client's.
      AIG-configured; no AIG documentation states which clients it bridges.
    standard: false
    vendor: Okta
  - name: emeasme
    description: >-
      AIG-specific custom scope. The name reads as EMEA + SME (small and medium enterprise), which
      would match AIG's EMEA small-business lines, but AIG publishes nothing that states its meaning
      or the resources it grants. Recorded as UNKNOWN — the reading is an observation, not a claim.
    standard: false
    vendor: AIG
    meaning: unknown
  - name: okta.myAccount.appAuthenticator.manage
    description: Manage the user's own Okta app authenticator enrollment.
    standard: false
    vendor: Okta
  - name: okta.myAccount.appAuthenticator.read
    description: Read the user's own Okta app authenticator enrollment.
    standard: false
    vendor: Okta
  - name: okta.myAccount.appAuthenticator.maintenance.manage
    description: Manage maintenance state of the user's own Okta app authenticator.
    standard: false
    vendor: Okta
  - name: okta.myAccount.appAuthenticator.maintenance.read
    description: Read maintenance state of the user's own Okta app authenticator.
    standard: false
    vendor: Okta
finding: >-
  Of the 13 scopes AIG's customer-platform authorization server advertises, 11 are stock OIDC or
  Okta platform scopes and exactly ONE (emeasme) is an AIG business scope. There is no scope that
  names an insurance resource — no policy, quote, claim, certificate or producer scope is exposed
  anonymously. Whatever authorization the commercial gateway applies is not expressed in the
  discoverable scope set.

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/american-international-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.