University of Hong Kong · OAuth Scopes
University of Hong Kong OAuth Scopes
OAuth 2.0
probed
University of Hong Kong publishes 9 OAuth 2.0 scopes via the authorizationCode, clientCredentials, and deviceCode flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the University of Hong Kong API on a user’s behalf.
Tokens are issued from https://adfs.hku.hk/adfs/oauth2/token/.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
EducationHigher EducationUniversityHong KongIdentity FederationSingle Sign-OnResearch DataOpen AccessArtificial IntelligenceResearch Computing
Scopes: 9
Flows: authorizationCode, clientCredentials, deviceCode
Method: probed
OAuth endpoints
Authorization URL
https://adfs.hku.hk/adfs/oauth2/authorize/
https://adfs.hku.hk/adfs/oauth2/authorize/
Token URL
https://adfs.hku.hk/adfs/oauth2/token/
https://adfs.hku.hk/adfs/oauth2/token/
Flows
authorizationCodeclientCredentialsdeviceCode
authorizationCodeclientCredentialsdeviceCode
Scopes (9)
| Scope | Description | Flows |
|---|---|---|
| openid | Standard OpenID Connect scope — issues an ID token for the signed-in HKU account. | authorizationCode, clientCredentials, deviceCode |
| profile | Releases profile claims (unique_name, upn) about the signed-in account. | authorizationCode |
| Releases the account's email claim. | authorizationCode | |
| allatclaims | AD FS scope that copies all claims from the underlying authentication into the issued token. | authorizationCode |
| aza | Microsoft broker scope used for primary refresh tokens on managed devices. | authorizationCode |
| user_impersonation | Allows a relying party to act on behalf of the signed-in user. | authorizationCode |
| logon_cert | Requests a logon certificate for certificate-based authentication. | authorizationCode |
| winhello_cert | Requests a Windows Hello for Business certificate. | authorizationCode |
| vpn_cert | Requests a VPN client certificate. | authorizationCode |
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.