Express Scripts Holding · OAuth Scopes

Express Scripts Holding OAuth Scopes

OAuth 2.0 probed

Express Scripts Holding uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

HealthHealthcarePharmacyPharmacy Benefit ManagementPrescriptionsClaimsFortune 100
Scopes: 0 Flows: Method: probed

Scopes (0)

Express Scripts Holding implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.

No scopes/permissions reference page is publicly reachable — the developer portal renders client-side and its content backend answers 403 to anonymous requests. Everything below is read from documents the provider serves anonymously. The one Express Scripts-specific scope in the estate is `esrx.default`; every other scope advertised on the default authorization server is a standard OIDC or Okta scope.

Source

OAuth Scopes

express-scripts-holding-scopes.yml Raw ↑
generated: '2026-09-07'
method: probed
source: >-
  scopes_supported from the two fetched OAuth/OIDC discovery documents, plus the
  scope array the developer portal's own OIDC client requests, read from
  https://developer.express-scripts.com/assets/index-F-3lEwAf.js
note: >-
  No scopes/permissions reference page is publicly reachable — the developer portal
  renders client-side and its content backend answers 403 to anonymous requests.
  Everything below is read from documents the provider serves anonymously. The one
  Express Scripts-specific scope in the estate is `esrx.default`; every other scope
  advertised on the default authorization server is a standard OIDC or Okta scope.
docs: null
docs_note: >-
  No public scopes reference found. The API-specific scopes behind `esrx.default`
  are not published and would need an authenticated portal session to enumerate.
authorization_servers:
  - issuer: https://p1-express-scripts.okta.com/oauth2/default
    vanity: https://p.login.developer.express-scripts.com/oauth2/default
    role: The authorization server the developer portal authenticates against.
  - issuer: https://p.login.developer.express-scripts.com
    role: >-
      Okta org-level authorization server. Advertises client_credentials and the Okta
      management scope set; not the partner API path.
scopes:
  - name: esrx.default
    source: portal-client
    first_party: true
    description: >-
      The Express Scripts application scope requested by the developer portal client.
      This is the only vendor-namespaced scope observed in the estate. What it grants
      is not published; the scope name is recorded, its permissions are not known.
    evidence: developer portal OIDC client scope array
  - name: openid
    source: discovery
    standard: OpenID Connect Core 1.0
    description: Requests an ID token. Required for any OIDC flow.
  - name: profile
    source: discovery
    standard: OpenID Connect Core 1.0
    description: Basic profile claims (name, preferred_username, locale, updated_at).
  - name: email
    source: discovery
    standard: OpenID Connect Core 1.0
    description: email and email_verified claims.
  - name: address
    source: discovery
    standard: OpenID Connect Core 1.0
    description: The address claim.
  - name: phone
    source: discovery
    standard: OpenID Connect Core 1.0
    description: phone_number and phone_number_verified claims.
  - name: offline_access
    source: discovery
    standard: OpenID Connect Core 1.0
    description: Requests a refresh token.
  - name: groups
    source: discovery
    server: org-level
    description: Group membership claim. Advertised on the org authorization server.
  - name: device_sso
    source: discovery
    server: default
    description: Okta device single sign-on.
  - name: interclient_access
    source: discovery
    server: default
    description: Okta cross-client token exchange.
counts:
  total: 10
  first_party: 1
  standard_oidc: 6
  vendor_platform: 3
gaps:
  - >-
    No per-API or per-operation scope is published. `esrx.default` is a single coarse
    application scope; there is no evidence of least-privilege scoping on the partner
    APIs, and no public document maps a scope to a capability.

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/express-scripts-holding-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.