AmTrust Financial Services · OAuth Scopes
AmTrust Financial Services OAuth Scopes
OAuth 2.0
searched
AmTrust Financial Services uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
Commercial InsuranceInsuranceProperty and CasualtySmall BusinessWorkers CompensationFortune 1000UnderwritingClaimsPolicyReinsuranceCyber InsuranceSurety
Scopes: 0
Flows:
Method: searched
Scopes (0)
AmTrust Financial Services implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.
These scopes come from AmTrust's own OpenID Connect discovery document, not from any OpenAPI securityScheme — none of the nine harvested OpenAPI documents declares an oauth2 or openIdConnect scheme, so `derive-oauth-scopes.py` correctly found nothing to derive. The scope set is coarse: it authenticates the caller and carries legacy portal identity, and does NOT partition the API surface. There is no read/write split, no per-product scope (workers' comp vs BOP vs claims vs reinsurance), and no per-operation scope. Authorization to a given API is enforced by the Azure API Management subscription (which product a subscriber_id is entitled to), not by the token.
These scopes come from AmTrust's own OpenID Connect discovery document, not from any OpenAPI securityScheme — none of the nine harvested OpenAPI documents declares an oauth2 or openIdConnect scheme, so `derive-oauth-scopes.py` correctly found nothing to derive. The scope set is coarse: it authenticates the caller and carries legacy portal identity, and does NOT partition the API surface. There is no read/write split, no per-product scope (workers' comp vs BOP vs claims vs reinsurance), and no per-operation scope. Authorization to a given API is enforced by the Azure API Management subscription (which product a subscriber_id is entitled to), not by the token.
📄 Provider scope reference: https://apiportal.amtrustgroup.com/authentication
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.