Flagsmith · OAuth Scopes
Flagsmith OAuth Scopes
OAuth 2.0
probed
Flagsmith uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
Feature FlagsRemote ConfigRelease ManagementA/B TestingExperimentationSegmentationDeveloper ToolsDevOpsOpen SourceSoftware-as-a-ServiceMCPAgent Ready
Scopes: 0
Flows:
Method: probed
Scopes (0)
Flagsmith implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.
Read from the provider's own RFC 8414 metadata rather than derived — derive-oauth-scopes.py finds nothing because the OpenAPI declares its security schemes as apiKey/http and never as oauth2, so the OAuth surface is invisible from the contract alone. It is only discoverable from the .well-known documents, which is exactly why they were probed. Two scopes, coarse-grained: there is no per-resource or read/write split, so an agent granted `mcp` can reach every tool the deployment exposes, and one granted `admin-api` can reach the Management API within the granting user's own permissions. Fine-grained restriction is done with Flagsmith's RBAC roles and permission groups, not with OAuth scopes.
Read from the provider's own RFC 8414 metadata rather than derived — derive-oauth-scopes.py finds nothing because the OpenAPI declares its security schemes as apiKey/http and never as oauth2, so the OAuth surface is invisible from the contract alone. It is only discoverable from the .well-known documents, which is exactly why they were probed. Two scopes, coarse-grained: there is no per-resource or read/write split, so an agent granted `mcp` can reach every tool the deployment exposes, and one granted `admin-api` can reach the Management API within the granting user's own permissions. Fine-grained restriction is done with Flagsmith's RBAC roles and permission groups, not with OAuth scopes.
📄 Provider scope reference: https://docs.flagsmith.com/integrating-with-flagsmith/mcp-server
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.