Fannie Mae · OAuth Scopes

Fannie Mae OAuth Scopes

OAuth 2.0 probed

Fannie Mae uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

Federal-GovernmentHousingMortgagesFinanceGSEFortune 100
Scopes: 0 Flows: Method: probed

Scopes (0)

Fannie Mae implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.

These are the scopes Fannie Mae's own OAuth 2.0 / OpenID Connect authorization server advertises, read from its published discovery document. Fannie Mae does NOT publish a scope reference page, and no public OpenAPI declares per-operation security requirements, so the mapping of scope to API operation is not public. Descriptions below marked `inferred: true` are our reading of the scope name, not a Fannie Mae definition — nothing here is quoted from a Fannie Mae scopes document, because no such document is published.

Source

OAuth Scopes

fannie-mae-scopes.yml Raw ↑
generated: '2026-09-07'
method: probed
source: >-
  scopes_supported from https://fmsso.fanniemae.com/.well-known/openid-configuration (HTTP 200,
  fetched 2026-09-07; saved verbatim as well-known/fannie-mae-fmsso-openid-configuration.json)
note: >-
  These are the scopes Fannie Mae's own OAuth 2.0 / OpenID Connect authorization server advertises,
  read from its published discovery document. Fannie Mae does NOT publish a scope reference page, and
  no public OpenAPI declares per-operation security requirements, so the mapping of scope to API
  operation is not public. Descriptions below marked `inferred: true` are our reading of the scope
  name, not a Fannie Mae definition — nothing here is quoted from a Fannie Mae scopes document,
  because no such document is published.
authorization_server: https://fmsso.fanniemae.com
docs: null
docs_note: No public OAuth scope reference page was found on any fanniemae.com host.
scope_count: 15
scopes:
  - name: openid
    description: Standard OpenID Connect scope — requests an ID token.
    inferred: false
    standard: OpenID Connect Core 1.0
  - name: profile
    description: Standard OpenID Connect scope — basic profile claims.
    inferred: false
    standard: OpenID Connect Core 1.0
  - name: email
    description: Standard OpenID Connect scope — email claims.
    inferred: false
    standard: OpenID Connect Core 1.0
  - name: address
    description: Standard OpenID Connect scope — address claim.
    inferred: false
    standard: OpenID Connect Core 1.0
  - name: phone
    description: Standard OpenID Connect scope — phone claims.
    inferred: false
    standard: OpenID Connect Core 1.0
  - name: idmz
    description: >-
      Requested by the Developer Portal client alongside openid and profile; observed in the live
      302 to the authorization endpoint. Appears to scope access to the internet-DMZ external-party
      surface.
    inferred: true
    observed_in_use: true
  - name: api-int.fanniemae.com
    description: >-
      Host-named scope. Names an internal API gateway host (api-int.fanniemae.com does not resolve
      publicly), which is direct evidence that Fannie Mae gates API access by target gateway.
    inferred: true
  - name: apigee_hostnamegroups
    description: >-
      Names Apigee hostname groups — evidence that the API gateway behind the developer program is
      Apigee.
    inferred: true
  - name: treasuryapps
    description: Scopes access to Fannie Mae treasury applications.
    inferred: true
  - name: pamfa
    description: Application-specific scope; the application it names is not publicly documented.
    inferred: true
  - name: extfromint
    description: External-from-internal federation scope.
    inferred: true
  - name: intextusers
    description: Internal/external user directory scope.
    inferred: true
  - name: p1cintext
    description: PingOne-cloud internal/external bridging scope.
    inferred: true
  - name: formloginonly
    description: Restricts the authentication experience to form login.
    inferred: true
  - name: write:user
    description: Write access to user records.
    inferred: true

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/fannie-mae-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.