BostonGene · OAuth Scopes

BostonGene OAuth Scopes

OAuth 2.0 probed

BostonGene publishes 36 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the BostonGene API on a user’s behalf.

Tokens are issued from https://bostongene.my.site.com/services/oauth2/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanyHealth CareOncologyPrecision MedicineGenomicsBioinformaticsArtificial IntelligenceDiagnosticsLife SciencesClinical Laboratory
Scopes: 36 Flows: authorizationCode Method: probed

OAuth endpoints

Authorization URL
https://bostongene.my.site.com/services/oauth2/authorize
Token URL
https://bostongene.my.site.com/services/oauth2/token
Flows
authorizationCode

Scopes (36)

ScopeDescriptionFlows
openid OpenID Connect — request an ID token
profile Standard OIDC profile claims
email Standard OIDC email claims
address Standard OIDC address claim
phone Standard OIDC phone claims
id Identity URL access
api Access the platform REST/SOAP APIs on behalf of the user
web Web session access
full Full access to all data accessible to the user
refresh_token Issue a refresh token
offline_access Offline access (refresh token equivalent)
custom_permissions Include the user's custom permissions in the token response
lightning Access Lightning applications
visualforce Access Visualforce pages
content Access content/files
chatter_api Access the Chatter/Connect REST API
chatbot_api Access the chatbot API
wave_api Access the analytics (Wave) API
eclair_api Access the Eclair geodata API
pardot_api Access the Pardot marketing automation API
interaction_api Access the interaction/flow API
user_registration_api Access the user registration API
pwdless_login_api Access the passwordless login API
forgot_password Access the forgot-password API
scrt_api Access the service-cloud real-time API
sfap_api Access the platform agent API
mcp_api Access the platform Model Context Protocol API surface
einstein_gpt_api Access the Einstein GPT API
data_cloud_user_claims Include Data Cloud user claims
cdp_api Access the Customer Data Platform API
cdp_query_api Access the CDP query API
cdp_ingest_api Access the CDP ingestion API
cdp_profile_api Access the CDP profile API
cdp_segment_api Access the CDP segmentation API
cdp_identityresolution_api Access the CDP identity resolution API
cdp_calculated_insight_api Access the CDP calculated insights API

Source

OAuth Scopes

bostongene-scopes.yml Raw ↑
generated: '2026-08-02'
method: probed
source: https://bostongene.my.site.com/.well-known/openid-configuration
provider_specific: false
note: >-
  These are the `scopes_supported` advertised verbatim by the OpenID Connect
  discovery document on BostonGene's customer-portal host. They are the standard
  Salesforce Experience Cloud platform scope set, not a BostonGene-authored API
  permission model — BostonGene publishes no developer API and no scope reference
  page. Recorded because the document is genuinely served from a BostonGene host;
  do NOT read this list as a BostonGene API authorization design.
schemes:
- name: BostonGene Customer Portal (OIDC)
  source: well-known/bostongene-openid-configuration.json
  issuer: https://bostongene.my.site.com
  flows:
  - flow: authorizationCode
    authorizationUrl: https://bostongene.my.site.com/services/oauth2/authorize
    tokenUrl: https://bostongene.my.site.com/services/oauth2/token
scopes:
- scope: openid
  description: OpenID Connect — request an ID token
- scope: profile
  description: Standard OIDC profile claims
- scope: email
  description: Standard OIDC email claims
- scope: address
  description: Standard OIDC address claim
- scope: phone
  description: Standard OIDC phone claims
- scope: id
  description: Identity URL access
- scope: api
  description: Access the platform REST/SOAP APIs on behalf of the user
- scope: web
  description: Web session access
- scope: full
  description: Full access to all data accessible to the user
- scope: refresh_token
  description: Issue a refresh token
- scope: offline_access
  description: Offline access (refresh token equivalent)
- scope: custom_permissions
  description: Include the user's custom permissions in the token response
- scope: lightning
  description: Access Lightning applications
- scope: visualforce
  description: Access Visualforce pages
- scope: content
  description: Access content/files
- scope: chatter_api
  description: Access the Chatter/Connect REST API
- scope: chatbot_api
  description: Access the chatbot API
- scope: wave_api
  description: Access the analytics (Wave) API
- scope: eclair_api
  description: Access the Eclair geodata API
- scope: pardot_api
  description: Access the Pardot marketing automation API
- scope: interaction_api
  description: Access the interaction/flow API
- scope: user_registration_api
  description: Access the user registration API
- scope: pwdless_login_api
  description: Access the passwordless login API
- scope: forgot_password
  description: Access the forgot-password API
- scope: scrt_api
  description: Access the service-cloud real-time API
- scope: sfap_api
  description: Access the platform agent API
- scope: mcp_api
  description: Access the platform Model Context Protocol API surface
- scope: einstein_gpt_api
  description: Access the Einstein GPT API
- scope: data_cloud_user_claims
  description: Include Data Cloud user claims
- scope: cdp_api
  description: Access the Customer Data Platform API
- scope: cdp_query_api
  description: Access the CDP query API
- scope: cdp_ingest_api
  description: Access the CDP ingestion API
- scope: cdp_profile_api
  description: Access the CDP profile API
- scope: cdp_segment_api
  description: Access the CDP segmentation API
- scope: cdp_identityresolution_api
  description: Access the CDP identity resolution API
- scope: cdp_calculated_insight_api
  description: Access the CDP calculated insights API
x-evidence:
  fetched: '2026-08-02'
  url: https://bostongene.my.site.com/.well-known/openid-configuration
  http_status: 200
  scope_count: 37