Fusio · OAuth Scopes

Fusio OAuth Scopes

OAuth 2.0 searched

Fusio publishes 58 OAuth 2.0 scopes via the clientCredentials and authorizationCode flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the Fusio API on a user’s behalf.

Tokens are issued from https://demo.fusio-project.org/authorization/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

API ManagementOpen-SourceREST APIAPI GatewayDeveloper PortalOpenAPISelf-HostedMCP
Scopes: 58 Flows: clientCredentials, authorizationCode Method: searched

OAuth endpoints

Authorization URL
https://demo.fusio-project.org/authorization/authorize
Token URL
https://demo.fusio-project.org/authorization/token
Flows
clientCredentialsauthorizationCode

Scopes (58)

ScopeDescriptionFlows
authorization authorizationCode, clientCredentials
backend authorizationCode, clientCredentials
backend.account authorizationCode, clientCredentials
backend.action authorizationCode, clientCredentials
backend.agent authorizationCode, clientCredentials
backend.app authorizationCode, clientCredentials
backend.audit authorizationCode, clientCredentials
backend.backup authorizationCode, clientCredentials
backend.bundle authorizationCode, clientCredentials
backend.category authorizationCode, clientCredentials
backend.config authorizationCode, clientCredentials
backend.connection authorizationCode, clientCredentials
backend.cronjob authorizationCode, clientCredentials
backend.dashboard authorizationCode, clientCredentials
backend.event authorizationCode, clientCredentials
backend.firewall authorizationCode, clientCredentials
backend.form authorizationCode, clientCredentials
backend.generator authorizationCode, clientCredentials
backend.identity authorizationCode, clientCredentials
backend.log authorizationCode, clientCredentials
backend.marketplace authorizationCode, clientCredentials
backend.operation authorizationCode, clientCredentials
backend.page authorizationCode, clientCredentials
backend.plan authorizationCode, clientCredentials
backend.rate authorizationCode, clientCredentials
backend.role authorizationCode, clientCredentials
backend.schema authorizationCode, clientCredentials
backend.scope authorizationCode, clientCredentials
backend.sdk authorizationCode, clientCredentials
backend.specification authorizationCode, clientCredentials
backend.statistic authorizationCode, clientCredentials
backend.taxonomy authorizationCode, clientCredentials
backend.tenant authorizationCode, clientCredentials
backend.test authorizationCode, clientCredentials
backend.token authorizationCode, clientCredentials
backend.transaction authorizationCode, clientCredentials
backend.trash authorizationCode, clientCredentials
backend.trigger authorizationCode, clientCredentials
backend.user authorizationCode, clientCredentials
backend.webhook authorizationCode, clientCredentials
consumer authorizationCode, clientCredentials
consumer.account authorizationCode, clientCredentials
consumer.agent authorizationCode, clientCredentials
consumer.app authorizationCode, clientCredentials
consumer.event authorizationCode, clientCredentials
consumer.form authorizationCode, clientCredentials
consumer.grant authorizationCode, clientCredentials
consumer.identity authorizationCode, clientCredentials
consumer.log authorizationCode, clientCredentials
consumer.page authorizationCode, clientCredentials
consumer.payment authorizationCode, clientCredentials
consumer.plan authorizationCode, clientCredentials
consumer.scope authorizationCode, clientCredentials
consumer.token authorizationCode, clientCredentials
consumer.transaction authorizationCode, clientCredentials
consumer.webhook authorizationCode, clientCredentials
openid OpenID scope authorizationCode, clientCredentials
system authorizationCode, clientCredentials

Source

OAuth Scopes

Raw ↑
generated: '2026-08-29'
method: searched
source: openapi/fusio-authorization.json, openapi/fusio-backend.json, openapi/fusio-consumer.json, openapi/fusio-system.json;
  scope semantics from https://docs.fusio-project.org/docs/security/authorization, https://docs.fusio-project.org/docs/security/personal_access_token
  and https://docs.fusio-project.org/docs/backend/system/role
schemes:
- name: app
  source: openapi/fusio-authorization.json
  flows:
  - flow: clientCredentials
    tokenUrl: https://demo.fusio-project.org/authorization/token
  - flow: authorizationCode
    authorizationUrl: https://demo.fusio-project.org/authorization/authorize
    tokenUrl: https://demo.fusio-project.org/authorization/token
- name: app
  source: openapi/fusio-backend.json
  flows:
  - flow: clientCredentials
    tokenUrl: https://demo.fusio-project.org/authorization/token
  - flow: authorizationCode
    authorizationUrl: https://demo.fusio-project.org/authorization/authorize
    tokenUrl: https://demo.fusio-project.org/authorization/token
- name: app
  source: openapi/fusio-consumer.json
  flows:
  - flow: clientCredentials
    tokenUrl: https://demo.fusio-project.org/authorization/token
  - flow: authorizationCode
    authorizationUrl: https://demo.fusio-project.org/authorization/authorize
    tokenUrl: https://demo.fusio-project.org/authorization/token
- name: app
  source: openapi/fusio-system.json
  flows:
  - flow: clientCredentials
    tokenUrl: https://demo.fusio-project.org/authorization/token
  - flow: authorizationCode
    authorizationUrl: https://demo.fusio-project.org/authorization/authorize
    tokenUrl: https://demo.fusio-project.org/authorization/token
scopes:
- scope: authorization
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-authorization.json
- scope: backend
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.account
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.action
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.agent
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.app
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.audit
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.backup
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.bundle
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.category
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.config
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.connection
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.cronjob
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.dashboard
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.event
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.firewall
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.form
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.generator
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.identity
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.log
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.marketplace
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.operation
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.page
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.plan
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.rate
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.role
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.schema
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.scope
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.sdk
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.specification
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.statistic
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.taxonomy
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.tenant
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.test
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.token
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.transaction
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.trash
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.trigger
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.user
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: backend.webhook
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-backend.json
- scope: consumer
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-consumer.json
- scope: consumer.account
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-consumer.json
- scope: consumer.agent
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-consumer.json
- scope: consumer.app
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-consumer.json
- scope: consumer.event
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-consumer.json
- scope: consumer.form
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-consumer.json
- scope: consumer.grant
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-consumer.json
- scope: consumer.identity
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-consumer.json
- scope: consumer.log
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-consumer.json
- scope: consumer.page
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-consumer.json
- scope: consumer.payment
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-consumer.json
- scope: consumer.plan
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-consumer.json
- scope: consumer.scope
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-consumer.json
- scope: consumer.token
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-consumer.json
- scope: consumer.transaction
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-consumer.json
- scope: consumer.webhook
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-consumer.json
- scope: openid
  description: OpenID scope
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-authorization.json
- scope: system
  flows:
  - authorizationCode
  - clientCredentials
  sources:
  - openapi/fusio-system.json
provider: Fusio
providerId: fusio
docs: https://docs.fusio-project.org/docs/security/authorization
description: 'Fusio''s scope model is namespaced by category and then by resource: ''backend'' grants
  the whole backend surface, ''backend.operation'' grants only the operation resource within it, and the
  same shape repeats for ''consumer''. Scopes are instance data, not product constants - an operator creates
  their own alongside these through backend.scope.create - so this list is the 58 scopes Fusio''s own
  reference instance defines for its management surface. Personal access tokens can be issued against
  any subset.'
namespaces:
- prefix: backend
  grants: the entire backend management surface
  narrower: backend.<resource>
- prefix: consumer
  grants: the entire developer-portal surface
  narrower: consumer.<resource>
- prefix: system
  grants: meta, health, route table and spec generation
- prefix: authorization
  grants: token introspection and revocation
- prefix: openid
  grants: OIDC claims when Fusio acts as an identity provider
- prefix: default
  grants: the scope every app receives; the only one advertised anonymously
roles_note: Scopes are granted to a user through a ROLE (backend.role.*), and a role belongs to a category.
  An operator assigns scopes to roles rather than to users directly.
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/fusio-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.