Caliza · OAuth Scopes

Caliza OAuth Scopes

OAuth 2.0 searched

Caliza publishes 10 OAuth 2.0 scopes via the password flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Caliza API on a user’s behalf.

Tokens are issued from https://api.caliza.com/auth/realms/caliza/protocol/openid-connect/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanyFintechPaymentsCross-Border PaymentsStablecoinsRemittancesForeign ExchangeVirtual AccountsPayoutsKYCLatin America
Scopes: 10 Flows: password Method: searched

OAuth endpoints

Token URL
https://api.caliza.com/auth/realms/caliza/protocol/openid-connect/token
Flows
password

Scopes (10)

ScopeDescriptionFlows
openid OpenID Connect authentication; issues an ID token identifying the integrator. password, authorizationCode
email Access to the integrator's email claim. password, authorizationCode
profile Access to the integrator's profile claims (name, preferred_username). password, authorizationCode
offline_access Issues a refresh token for long-lived offline access. password, authorizationCode
roles Includes realm/client role mappings in the token. password, authorizationCode
address Access to address claims. authorizationCode
phone Access to phone-number claims. authorizationCode
web-origins Populates allowed CORS web origins. authorizationCode
microprofile-jwt MicroProfile JWT claims mapping. authorizationCode
acr Authentication Context Class Reference claim. authorizationCode

Source

OAuth Scopes

caliza-scopes.yml Raw ↑
generated: '2026-07-18'
method: searched
source: https://api.caliza.com/auth/realms/caliza/.well-known/openid-configuration
docs: https://docs.caliza.com/docs/authenticate
schemes:
- name: OAuth2 (Keycloak realm "caliza")
  source: well-known/caliza-openid-configuration.json
  flows:
  - flow: password
    tokenUrl: https://api.caliza.com/auth/realms/caliza/protocol/openid-connect/token
scopes:
- scope: openid
  description: OpenID Connect authentication; issues an ID token identifying the integrator.
  flows: [password, authorizationCode]
- scope: email
  description: Access to the integrator's email claim.
  flows: [password, authorizationCode]
- scope: profile
  description: Access to the integrator's profile claims (name, preferred_username).
  flows: [password, authorizationCode]
- scope: offline_access
  description: Issues a refresh token for long-lived offline access.
  flows: [password, authorizationCode]
- scope: roles
  description: Includes realm/client role mappings in the token.
  flows: [password, authorizationCode]
- scope: address
  description: Access to address claims.
  flows: [authorizationCode]
- scope: phone
  description: Access to phone-number claims.
  flows: [authorizationCode]
- scope: web-origins
  description: Populates allowed CORS web origins.
  flows: [authorizationCode]
- scope: microprofile-jwt
  description: MicroProfile JWT claims mapping.
  flows: [authorizationCode]
- scope: acr
  description: Authentication Context Class Reference claim.
  flows: [authorizationCode]
notes: >-
  Scopes are the standard Keycloak/OIDC scope set advertised by the realm
  discovery document; the documented quickstart token response returns
  "scope": "email openid profile". API-level authorization is enforced through
  realm roles (e.g. ROLE_CREATE_TRANSACTIONS, ROLE_VIEW_ACTIVITY,
  ROLE_MANAGE_PAYMENT_CONTACTS) carried inside the access-token JWT rather than
  through granular OAuth resource scopes.