Green Check Verified · OAuth Scopes
Green Check Verified OAuth Scopes
OAuth 2.0
searched
Green Check Verified publishes 10 OAuth 2.0 scopes via the client_credentials flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Green Check Verified API on a user’s behalf.
Tokens are issued from https://prod-api.greencheckverified.com/auth/token.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
CompanyCannabisComplianceBankingFinancial ServicesBSA/AMLRegTechPoint-of-SaleOnboardingDue DiligenceKYCData Aggregation
Scopes: 10
Flows: client_credentials
Method: searched
OAuth endpoints
Token URL
https://prod-api.greencheckverified.com/auth/token
https://prod-api.greencheckverified.com/auth/token
Flows
client_credentials
client_credentials
Scopes (10)
| Scope | Description | Flows |
|---|---|---|
| service-provider:read | Read the calling service provider's own organization record, its connected CRBs, POS credential schemas, license search, onboarding templates and CRB profiles. | |
| service-provider:write | Create a CRB under the calling service provider (POST /service-providers/{sp_id}/crbs). | |
| point-of-sale:read | Read POS-sourced operational data for a connected CRB — sales, products, inventory, inventory locations, customers and documents. | |
| point-of-sale:write | Applied to the CRB customer-search operation (GET .../customers-search). Note this is a read in HTTP terms but is scoped as a write in the contract. | |
| crb:read | Read a CRB directly by crb_id, and list/read that CRB's documents, on the CRB-scoped (non service-provider) routes. | |
| ein:read | Search existing CRBs by EIN (GET /service-providers/{sp_id}/ein-search). | |
| connect-crb-to-sp:write | Connect an existing CRB to the calling service provider by CRB_ID. | |
| create-crb-api-key:write | Generate Green Check Access credentials on behalf of a CRB so the service provider can operate that CRB's document-management calls. | |
| trace | Use the Trace proxy pass-through to state contracted track-and-trace systems (all HTTP methods on /trace/*). | |
| admin | Present as an alternative on every operation except the token endpoint. A token carrying `admin` satisfies the requirement on all 48 secured operations, including every Trace write. This is the one scope an integrator should never accept if a narrower one will do. |
📄 Provider scope reference: https://developer.greencheckverified.com/guides/integration-overview
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.