DoubleVerify · OAuth Scopes
DoubleVerify OAuth Scopes
OAuth 2.0
probed
DoubleVerify publishes 21 OAuth 2.0 scopes via the authorizationCode, clientCredentials, and deviceCode flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the DoubleVerify API on a user’s behalf.
Tokens are issued from https://dv-ciam.doubleverify.com/realms/pinnacle/protocol/openid-connect/token.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
Ad VerificationAd MeasurementMedia QualityBrand SuitabilityViewabilityAttention MeasurementInvalid TrafficFraud DetectionContextual TargetingProgrammatic AdvertisingConnected TVSocial Media MeasurementCommerce MediaPublisher AnalyticsMRC AccreditedAdTech
Scopes: 21
Flows: authorizationCode, clientCredentials, deviceCode
Method: probed
OAuth endpoints
Authorization URL
https://dv-ciam.doubleverify.com/realms/pinnacle/protocol/openid-connect/auth
https://dv-ciam.doubleverify.com/realms/pinnacle/protocol/openid-connect/auth
Token URL
https://dv-ciam.doubleverify.com/realms/pinnacle/protocol/openid-connect/token
https://dv-ciam.doubleverify.com/realms/pinnacle/protocol/openid-connect/token
Flows
authorizationCodeclientCredentialsdeviceCode
authorizationCodeclientCredentialsdeviceCode
Scopes (21)
| Scope | Description | Flows |
|---|---|---|
| openid | Standard OIDC scope; requests an ID token. | |
| Standard OIDC scope; releases the email and email_verified claims. | ||
| profile | Standard OIDC scope; releases basic profile claims. | |
| address | Standard OIDC scope; releases the address claim. | |
| phone | Standard OIDC scope; releases phone_number claims. | |
| offline_access | Standard OIDC scope; requests a refresh token for offline use. | |
| roles | Keycloak built-in; adds realm and client role mappings to the token. | |
| roles-limited | A narrowed variant of the roles mapper. | |
| web-origins | Keycloak built-in; adds allowed CORS web origins to the token. | |
| microprofile-jwt | Keycloak built-in; emits MicroProfile JWT claims (upn, groups). | |
| acr | Keycloak built-in; authentication context class reference. | |
| amr | Keycloak built-in; authentication methods references. | |
| basic | Keycloak built-in; core token claims (sub, auth_time). | |
| service_account | Keycloak built-in; marks a client-credentials service-account token. | |
| dv-agent-mcp-aud | DoubleVerify-specific audience scope for the DV Neura MCP agent surface. Its presence in the Pinnacle realm is the realm-side counterpart of the MCP server at mcp.doubleverify.com. | |
| dv-agent-mcp-internal-aud | DoubleVerify-specific audience scope for an internal DV Neura MCP surface, distinct from the client-facing one above. | |
| dv-apis-aud | DoubleVerify-specific audience scope for DV's API estate. | |
| dv-attributes | DoubleVerify-specific scope releasing DV account/entitlement attributes into the token. | |
| ums-aud | DoubleVerify-specific audience scope for a user-management service. | |
| salesforce-id | DoubleVerify-specific scope releasing the linked Salesforce account identifier. | |
| impersonation | Keycloak token-exchange impersonation scope. |