Essendant · OAuth Scopes

Essendant OAuth Scopes

OAuth 2.0 probed

Essendant publishes 9 OAuth 2.0 scopes via the authorizationCode, clientCredentials, and deviceCode flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the Essendant API on a user’s behalf.

Tokens are issued from https://sso.essendant.com/adfs/oauth2/token/.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

WholesaleDistributionSupply ChainOffice SuppliesFulfillment3PLB2BEDIEcommerceJanSanFoodservice
Scopes: 9 Flows: authorizationCode, clientCredentials, deviceCode Method: probed

OAuth endpoints

Authorization URL
https://sso.essendant.com/adfs/oauth2/authorize/ https://login.essendant.com/adfs/oauth2/authorize/
Token URL
https://sso.essendant.com/adfs/oauth2/token/ https://login.essendant.com/adfs/oauth2/token/
Flows
authorizationCodeclientCredentialsdeviceCode

Scopes (9)

ScopeDescriptionFlows
openid OpenID Connect sign-in; issues an id_token. authorizationCode
profile Profile claims about the signed-in user. authorizationCode
email Email claim for the signed-in user. authorizationCode
allatclaims AD FS scope requesting that all claims be included in the access token. authorizationCode
user_impersonation AD FS delegation scope — act on behalf of the signed-in user. authorizationCode
aza AD FS broker/primary-refresh-token scope. authorizationCode
logon_cert AD FS scope for issuing a logon certificate. authorizationCode
vpn_cert AD FS scope for issuing a VPN certificate. authorizationCode
winhello_cert AD FS scope for issuing a Windows Hello for Business certificate. authorizationCode

Source

OAuth Scopes

essendant-scopes.yml Raw ↑
generated: '2026-09-07'
method: probed
source: https://sso.essendant.com/adfs/.well-known/openid-configuration
note: >-
  These are the scopes advertised by Essendant's AD FS OpenID Connect discovery documents.
  They are the AD FS default set — Essendant has not defined API-specific scopes, because
  it publishes no API. No scopes/permissions reference page exists on essendant.com. Kept
  as an honest record of what the discovery document actually advertises.
schemes:
- name: essendant-adfs-sso
  source: well-known/essendant-sso-openid-configuration.json
  flows:
  - flow: authorizationCode
    authorizationUrl: https://sso.essendant.com/adfs/oauth2/authorize/
    tokenUrl: https://sso.essendant.com/adfs/oauth2/token/
  - flow: clientCredentials
    tokenUrl: https://sso.essendant.com/adfs/oauth2/token/
  - flow: deviceCode
    deviceAuthorizationUrl: https://sso.essendant.com/adfs/oauth2/devicecode
    tokenUrl: https://sso.essendant.com/adfs/oauth2/token/
- name: essendant-adfs-login
  source: well-known/essendant-login-openid-configuration.json
  flows:
  - flow: authorizationCode
    authorizationUrl: https://login.essendant.com/adfs/oauth2/authorize/
    tokenUrl: https://login.essendant.com/adfs/oauth2/token/
scopes:
- scope: openid
  description: OpenID Connect sign-in; issues an id_token.
  flows: [authorizationCode]
  sources: [well-known/essendant-sso-openid-configuration.json, well-known/essendant-login-openid-configuration.json]
- scope: profile
  description: Profile claims about the signed-in user.
  flows: [authorizationCode]
  sources: [well-known/essendant-sso-openid-configuration.json, well-known/essendant-login-openid-configuration.json]
- scope: email
  description: Email claim for the signed-in user.
  flows: [authorizationCode]
  sources: [well-known/essendant-sso-openid-configuration.json, well-known/essendant-login-openid-configuration.json]
- scope: allatclaims
  description: AD FS scope requesting that all claims be included in the access token.
  flows: [authorizationCode]
  sources: [well-known/essendant-sso-openid-configuration.json, well-known/essendant-login-openid-configuration.json]
- scope: user_impersonation
  description: AD FS delegation scope — act on behalf of the signed-in user.
  flows: [authorizationCode]
  sources: [well-known/essendant-sso-openid-configuration.json, well-known/essendant-login-openid-configuration.json]
- scope: aza
  description: AD FS broker/primary-refresh-token scope.
  flows: [authorizationCode]
  sources: [well-known/essendant-sso-openid-configuration.json, well-known/essendant-login-openid-configuration.json]
- scope: logon_cert
  description: AD FS scope for issuing a logon certificate.
  flows: [authorizationCode]
  sources: [well-known/essendant-sso-openid-configuration.json, well-known/essendant-login-openid-configuration.json]
- scope: vpn_cert
  description: AD FS scope for issuing a VPN certificate.
  flows: [authorizationCode]
  sources: [well-known/essendant-sso-openid-configuration.json, well-known/essendant-login-openid-configuration.json]
- scope: winhello_cert
  description: AD FS scope for issuing a Windows Hello for Business certificate.
  flows: [authorizationCode]
  sources: [well-known/essendant-sso-openid-configuration.json, well-known/essendant-login-openid-configuration.json]
docs: null

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/essendant-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.