Candis · OAuth Scopes
Candis OAuth Scopes
OAuth 2.0
searched
Candis publishes 13 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Candis API on a user’s behalf.
Tokens are issued from https://id.my.candis.io/auth/realms/candis/protocol/openid-connect/token.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
CompanyFintechAccounts PayableSpend ManagementInvoice ManagementFinancial Process AutomationAccountingDATEVOCRGermany
Scopes: 13
Flows: authorizationCode
Method: searched
OAuth endpoints
Authorization URL
https://id.my.candis.io/auth/realms/candis/protocol/openid-connect/auth
https://id.my.candis.io/auth/realms/candis/protocol/openid-connect/auth
Token URL
https://id.my.candis.io/auth/realms/candis/protocol/openid-connect/token
https://id.my.candis.io/auth/realms/candis/protocol/openid-connect/token
Flows
authorizationCode
authorizationCode
Scopes (13)
| Scope | Description | Flows |
|---|---|---|
| exports | Access to the Export API (create/read exports and exported postings, download export files). | authorizationCode |
| core_data | Access to the Core Data API (import/update general ledger accounts, cost dimensions, additional delivery costs, contacts). | authorizationCode |
| offline_access | Issues long-lived refresh tokens so token exchanges remain valid for an extended period (~6-24 months) without re-login; for long-running/background services. | authorizationCode, clientCredentials |
| service_account | Service-account (client-credentials) scope for machine-to-machine access. | clientCredentials |
| openid | Standard OpenID Connect scope (ID token). | authorizationCode |
| User email claim. Core scope, enabled by default. | ||
| profile | User profile claims. Core scope, enabled by default. | |
| address | User address claims (OIDC). | |
| phone | User phone claims (OIDC). | |
| roles | Realm/client role claims (Keycloak). | |
| acr | Authentication Context Class Reference (OIDC). | |
| microprofile-jwt | MicroProfile JWT claims (Keycloak). | |
| web-origins | Allowed web origins claim (Keycloak). |
📄 Provider scope reference: https://developer.candis.io/docs/access-token-scopes