MoMo · OAuth Scopes
MoMo OAuth Scopes
OAuth 2.0
searched
MoMo uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
PaymentsMobile PaymentsFintechDigital WalletPayment GatewayQR PaymentsDisbursementBuy Now Pay LaterE-CommerceVietnam
Scopes: 0
Flows:
Method: searched
Scopes (0)
MoMo implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.
MoMo's Mini App Open Platform is described in its own documentation as "based on the industry standard OAuth2.0 authorization mechanism", but it does NOT publish RFC 6749 scope strings. What it publishes instead is a consent-role vocabulary: a Mini App calls MiniApi.requestUserConsents with an array of permission roles, MoMo renders a bottom sheet, and the user grants or denies each role individually. The resulting authCode/accessToken carries whatever the user granted. These roles are the closest thing MoMo has to scopes and are recorded here verbatim from the Consents Request page. The dedicated "Permissions" page on the same site is published but EMPTY — its entire body reads "( to be updated )" — so there is no authoritative permission reference beyond this list.
MoMo's Mini App Open Platform is described in its own documentation as "based on the industry standard OAuth2.0 authorization mechanism", but it does NOT publish RFC 6749 scope strings. What it publishes instead is a consent-role vocabulary: a Mini App calls MiniApi.requestUserConsents with an array of permission roles, MoMo renders a bottom sheet, and the user grants or denies each role individually. The resulting authCode/accessToken carries whatever the user granted. These roles are the closest thing MoMo has to scopes and are recorded here verbatim from the Consents Request page. The dedicated "Permissions" page on the same site is published but EMPTY — its entire body reads "( to be updated )" — so there is no authoritative permission reference beyond this list.
📄 Provider scope reference: https://developers.momo.vn/v3/docs/app-center/development-guideline/open-capabilities/permissions/
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.