CARTO · OAuth Scopes
CARTO OAuth Scopes
OAuth 2.0
searched
CARTO publishes 4 OAuth 2.0 scopes via the authorizationCode and clientCredentials flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the CARTO API on a user’s behalf.
Tokens are issued from https://auth.carto.com/oauth/token.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
CompanyDeveloper ToolsLocation IntelligenceGeospatialMapsSpatial AnalyticsData WarehouseGISAgents
Scopes: 4
Flows: authorizationCode, clientCredentials
Method: searched
OAuth endpoints
Authorization URL
https://auth.carto.com/authorize
https://auth.carto.com/authorize
Token URL
https://auth.carto.com/oauth/token
https://auth.carto.com/oauth/token
Flows
authorizationCodeclientCredentials
authorizationCodeclientCredentials
Scopes (4)
| Scope | Description | Flows |
|---|---|---|
| openid | OIDC authentication; issue an ID token. | |
| profile | Access the user's basic profile claims. | |
| Access the user's email and email_verified claims. | ||
| offline_access | Issue a refresh token for long-lived access. |
📄 Provider scope reference: https://docs.carto.com/carto-for-developers/key-concepts/authentication-methods