Deep Instinct · OAuth Scopes

Deep Instinct OAuth Scopes

OAuth 2.0 probed

Deep Instinct publishes 2 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Deep Instinct API on a user’s behalf.

Tokens are issued from https://portal.deepinstinct.com/oauth/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

cybersecurityendpoint-securitymalware-preventionransomwaredeep-learningthreat-preventiondata-securityedrsoc-automationmcp
Scopes: 2 Flows: authorizationCode Method: probed

OAuth endpoints

Authorization URL
https://portal.deepinstinct.com/oauth/authorize
Token URL
https://portal.deepinstinct.com/oauth/token
Flows
authorizationCode

Scopes (2)

ScopeDescriptionFlows
mcp:read Read access through the portal MCP server. Description is not published by Deep Instinct; the scope string is verbatim from scopes_supported in both discovery documents. authorizationCode
mcp:write Write access through the portal MCP server. Description is not published by Deep Instinct; the scope string is verbatim from scopes_supported in both discovery documents. authorizationCode

Source

OAuth Scopes

deep-instinct-scopes.yml Raw ↑
generated: '2026-08-01'
method: probed
source: https://portal.deepinstinct.com/.well-known/oauth-authorization-server
note: >-
  Deep Instinct publishes no OpenAPI with oauth2 securitySchemes, so there is no spec to derive from.
  These scopes were read verbatim from the live RFC 8414 authorization-server metadata and the RFC 9728
  protected-resource metadata on portal.deepinstinct.com, which front the portal MCP server. The DSX
  management REST API uses an API key rather than OAuth and contributes no scopes.
schemes:
- name: portal-oauth
  type: oauth2
  issuer: https://portal.deepinstinct.com
  source: https://portal.deepinstinct.com/.well-known/oauth-authorization-server
  flows:
  - flow: authorizationCode
    authorizationUrl: https://portal.deepinstinct.com/oauth/authorize
    tokenUrl: https://portal.deepinstinct.com/oauth/token
    refreshUrl: https://portal.deepinstinct.com/oauth/token
    code_challenge_methods: [S256]
scopes:
- scope: mcp:read
  description: >-
    Read access through the portal MCP server. Description is not published by Deep Instinct; the scope
    string is verbatim from scopes_supported in both discovery documents.
  flows: [authorizationCode]
  sources:
  - well-known/deep-instinct-oauth-authorization-server.json
  - well-known/deep-instinct-oauth-protected-resource.json
- scope: mcp:write
  description: >-
    Write access through the portal MCP server. Description is not published by Deep Instinct; the scope
    string is verbatim from scopes_supported in both discovery documents.
  flows: [authorizationCode]
  sources:
  - well-known/deep-instinct-oauth-authorization-server.json
  - well-known/deep-instinct-oauth-protected-resource.json
resource:
  resource: https://portal.deepinstinct.com/mcp
  authorization_servers: [https://portal.deepinstinct.com]
  bearer_methods_supported: [header]
x-evidence:
  fetched: '2026-08-01'
  url: https://portal.deepinstinct.com/.well-known/oauth-authorization-server
  http_status: 200
  content_type: application/json