Elk · OAuth Scopes
Elk OAuth Scopes
OAuth 2.0
derived
Elk uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
FediverseMastodonOpen-SourceSocial NetworkingSocial-MediaWeb-ClientProgressive Web AppAuthentication
Scopes: 0
Flows:
Method: derived
Scopes (0)
Elk implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.
THESE ARE MASTODON'S SCOPES, NOT ELK'S. Elk does not define a permission vocabulary; it requests a fixed, non-configurable set of top-level Mastodon scopes on every sign-in and never asks for less. That is a real finding about Elk's consent posture: a user signing into Elk cannot grant read-only access, because the client hard-codes write, follow and push alongside read. There is no incremental or per-feature consent.
THESE ARE MASTODON'S SCOPES, NOT ELK'S. Elk does not define a permission vocabulary; it requests a fixed, non-configurable set of top-level Mastodon scopes on every sign-in and never asks for less. That is a real finding about Elk's consent posture: a user signing into Elk cannot grant read-only access, because the client hard-codes write, follow and push alongside read. There is no incremental or per-feature consent.
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.