Hexagon · OAuth Scopes

Hexagon OAuth Scopes

OAuth 2.0 probed

Hexagon uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

ManufacturingMetrologyQuality InspectionDigital FactoryProduction MonitoringIndustrial IoTSmart Manufacturing
Scopes: 0 Flows: Method: probed

Scopes (0)

Hexagon implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.

Source

OAuth Scopes

Raw ↑
generated: '2026-09-13'
method: probed
source: >-
  scopes_supported read verbatim from
  https://hxauth.com/auth/realms/geo-hxdr-prod/.well-known/openid-configuration
  (HTTP 200) and from
  https://geocloud.hexagon.com/.well-known/oauth-authorization-server (HTTP 200).
docs: null
docs_note: >-
  No scope or permission reference page is published anywhere on the public
  Hexagon GeoCloud or Leica Geosystems documentation surface. The descriptions
  below are the standard OIDC/Keycloak meanings where the scope is a standard one,
  and are marked undocumented where the scope is Hexagon-specific - the realm
  publishes the names but no prose.
authorization_servers:
  - issuer: https://hxauth.com/auth/realms/geo-hxdr-prod
    applies_to: hexagon-ab:geocloud-graphql
    scopes:
      - name: openid
        description: Standard OIDC scope requesting an ID token.
        standard: true
      - name: profile
        description: Standard OIDC claim set - name, given_name, family_name, preferred_username.
        standard: true
      - name: email
        description: Standard OIDC email claim.
        standard: true
      - name: address
        description: Standard OIDC address claim.
        standard: true
      - name: phone
        description: Standard OIDC phone claim.
        standard: true
      - name: offline_access
        description: Standard OIDC scope requesting a refresh token usable while the user is offline.
        standard: true
      - name: roles
        description: Keycloak built-in scope adding realm and client role mappings to the token.
        standard: false
      - name: web-origins
        description: Keycloak built-in scope adding allowed CORS origins to the token.
        standard: false
      - name: acr
        description: Keycloak built-in scope carrying the authentication context class reference.
        standard: false
      - name: basic
        description: Keycloak built-in scope carrying the minimal sub/auth_time claim set.
        standard: false
      - name: microprofile-jwt
        description: Keycloak built-in scope emitting MicroProfile JWT claims (upn, groups).
        standard: false
      - name: user
        description: Hexagon-specific. Undocumented.
        standard: false
        documented: false
      - name: admin
        description: Hexagon-specific. Undocumented - name implies elevated administrative access.
        standard: false
        documented: false
      - name: service_account
        description: >-
          Hexagon-specific. Undocumented - name implies the non-interactive
          client_credentials identity.
        standard: false
        documented: false
      - name: hxdr_client_scope
        description: Hexagon-specific HxDR client scope. Undocumented.
        standard: false
        documented: false
      - name: hxdr_claims
        description: Hexagon-specific HxDR claim set. Undocumented.
        standard: false
        documented: false
      - name: hxdr_be_system_user
        description: >-
          Hexagon-specific HxDR back-end system-user scope. Undocumented - name
          implies a server-to-server identity.
        standard: false
        documented: false
  - issuer: https://geocloud.hexagon.com
    applies_to: hexagon-ab:geocloud-mcp
    scopes:
      - name: mcp
        description: >-
          The single scope the GeoCloud MCP authorization server advertises,
          required as the bearer scope for
          https://geocloud.hexagon.com/wp-json/mcp/mcp-oauth-server.
        standard: false
        documented: false
scope_count: 18

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/hexagon-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.