Medblocks · OAuth Scopes
Medblocks OAuth Scopes
OAuth 2.0
probed
Medblocks uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
HealthHealthcareFHIRopenEHRInteroperabilityElectronic Health RecordsPatient AccessHealth DataSMART on FHIRWebhooksModel Context ProtocolCompany
Scopes: 0
Flows:
Method: probed
Scopes (0)
Medblocks implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.
These scopes are NOT declared in openapi/medblocks-platform-openapi.json, which secures every operation with a single bearer API key (BearerAuth). They belong to the OAuth authorization server that fronts the hosted MCP server, and they were read from the provider's own RFC 8414 and RFC 9728 metadata documents plus the RFC 6750 challenge the MCP endpoint returns to an unauthenticated caller. The three tick boxes a user sees on the consent screen are a product-level grouping over these scopes; the mapping between the two is not published, so the consent grouping is recorded separately rather than asserted against individual scopes.
These scopes are NOT declared in openapi/medblocks-platform-openapi.json, which secures every operation with a single bearer API key (BearerAuth). They belong to the OAuth authorization server that fronts the hosted MCP server, and they were read from the provider's own RFC 8414 and RFC 9728 metadata documents plus the RFC 6750 challenge the MCP endpoint returns to an unauthenticated caller. The three tick boxes a user sees on the consent screen are a product-level grouping over these scopes; the mapping between the two is not published, so the consent grouping is recorded separately rather than asserted against individual scopes.
📄 Provider scope reference: https://medblocks.com/docs/mcp
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.