Omnisend · OAuth Scopes

Omnisend OAuth Scopes

OAuth 2.0 searched

Omnisend publishes 20 OAuth 2.0 scopes via the clientCredentials flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Omnisend API on a user’s behalf.

Tokens are issued from https://app.omnisend.com/oauth2/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

Email MarketingMarketing AutomationE-CommerceSMS MarketingCustomer EngagementSegmentationCampaignsFormsPopupsWeb PushAutomation WorkflowsAnalyticsMCPAgent ReadyTransactional Messaging
Scopes: 20 Flows: clientCredentials Method: searched

OAuth endpoints

Token URL
https://app.omnisend.com/oauth2/token
Flows
clientCredentials

Scopes (20)

ScopeDescriptionFlows
analytics.read
automations.read Read access to automations clientCredentials
automations.write Write access to automations clientCredentials
brands.read
brands.write
campaigns.read Read access to campaigns clientCredentials
campaigns.write Write access to campaigns clientCredentials
contacts.read Read contacts clientCredentials
contacts.write Create, update and delete contacts clientCredentials
email-templates.read Allows reading email templates and universal layouts clientCredentials
email-templates.write Allows create, update, delete email templates and universal layouts clientCredentials
events.read
events.write
images.read Allows reading images clientCredentials
images.write Allows uploading and deleting images clientCredentials
none No scopes required — authorization is not enforced via OAuth2 scopes clientCredentials
products.read Grants read access to product data clientCredentials
products.write Grants write access to product data clientCredentials
segments.read Read segments clientCredentials
segments.write Create, update and delete segments clientCredentials

Source

OAuth Scopes

Raw ↑
generated: '2026-08-13'
method: searched
source: https://mcp.omnisend.com/.well-known/oauth-authorization-server (RFC 8414 scopes_supported), https://mcp.omnisend.com/.well-known/oauth-protected-resource
  (RFC 9728 scopes_supported), https://api-docs.omnisend.com/reference/oauth, per-operation "Scopes:" notes in https://api-docs.omnisend.com/llms.txt,
  and openapi/omnisend-*-openapi.yml
schemes:
- name: Bearer
  source: openapi/omnisend-analytics-api-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: https://app.omnisend.com/oauth2/token
- name: Bearer
  source: openapi/omnisend-automations-api-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: https://app.omnisend.com/oauth2/token
- name: Bearer
  source: openapi/omnisend-batches-api-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: https://app.omnisend.com/oauth2/token
- name: Bearer
  source: openapi/omnisend-brands-api-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: https://app.omnisend.com/oauth2/token
- name: Bearer
  source: openapi/omnisend-campaigns-api-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: https://app.omnisend.com/oauth2/token
- name: Bearer
  source: openapi/omnisend-contacts-api-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: https://app.omnisend.com/oauth2/token
- name: Bearer
  source: openapi/omnisend-emailcontent-api-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: https://app.omnisend.com/oauth2/token
- name: Bearer
  source: openapi/omnisend-emailtemplates-api-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: https://app.omnisend.com/oauth2/token
- name: Bearer
  source: openapi/omnisend-emailuniversallayouts-api-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: https://app.omnisend.com/oauth2/token
- name: Bearer
  source: openapi/omnisend-event-metadata-api-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: https://app.omnisend.com/oauth2/token
- name: Bearer
  source: openapi/omnisend-events-api-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: https://app.omnisend.com/oauth2/token
- name: Bearer
  source: openapi/omnisend-images-api-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: https://app.omnisend.com/oauth2/token
- name: Bearer
  source: openapi/omnisend-productcategories-api-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: https://app.omnisend.com/oauth2/token
- name: Bearer
  source: openapi/omnisend-products-api-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: https://app.omnisend.com/oauth2/token
- name: Bearer
  source: openapi/omnisend-segments-api-openapi.yml
  flows:
  - flow: clientCredentials
    tokenUrl: https://app.omnisend.com/oauth2/token
scopes:
- scope: analytics.read
  sources:
  - openapi/omnisend-analytics-api-openapi.yml
- scope: automations.read
  description: Read access to automations
  flows:
  - clientCredentials
  sources:
  - openapi/omnisend-automations-api-openapi.yml
- scope: automations.write
  description: Write access to automations
  flows:
  - clientCredentials
  sources:
  - openapi/omnisend-automations-api-openapi.yml
- scope: brands.read
  sources:
  - openapi/omnisend-brands-api-openapi.yml
- scope: brands.write
  sources:
  - openapi/omnisend-brands-api-openapi.yml
- scope: campaigns.read
  description: Read access to campaigns
  flows:
  - clientCredentials
  sources:
  - openapi/omnisend-campaigns-api-openapi.yml
- scope: campaigns.write
  description: Write access to campaigns
  flows:
  - clientCredentials
  sources:
  - openapi/omnisend-campaigns-api-openapi.yml
- scope: contacts.read
  description: Read contacts
  flows:
  - clientCredentials
  sources:
  - openapi/omnisend-batches-api-openapi.yml
  - openapi/omnisend-contacts-api-openapi.yml
- scope: contacts.write
  description: Create, update and delete contacts
  flows:
  - clientCredentials
  sources:
  - openapi/omnisend-batches-api-openapi.yml
  - openapi/omnisend-contacts-api-openapi.yml
- scope: email-templates.read
  description: Allows reading email templates and universal layouts
  flows:
  - clientCredentials
  sources:
  - openapi/omnisend-emailcontent-api-openapi.yml
  - openapi/omnisend-emailtemplates-api-openapi.yml
  - openapi/omnisend-emailuniversallayouts-api-openapi.yml
- scope: email-templates.write
  description: Allows create, update, delete email templates and universal layouts
  flows:
  - clientCredentials
  sources:
  - openapi/omnisend-emailcontent-api-openapi.yml
  - openapi/omnisend-emailtemplates-api-openapi.yml
  - openapi/omnisend-emailuniversallayouts-api-openapi.yml
- scope: events.read
  sources:
  - openapi/omnisend-batches-api-openapi.yml
- scope: events.write
  sources:
  - openapi/omnisend-batches-api-openapi.yml
  - openapi/omnisend-events-api-openapi.yml
- scope: images.read
  description: Allows reading images
  flows:
  - clientCredentials
  sources:
  - openapi/omnisend-images-api-openapi.yml
- scope: images.write
  description: Allows uploading and deleting images
  flows:
  - clientCredentials
  sources:
  - openapi/omnisend-images-api-openapi.yml
- scope: none
  description: No scopes required — authorization is not enforced via OAuth2 scopes
  flows:
  - clientCredentials
  sources:
  - openapi/omnisend-event-metadata-api-openapi.yml
- scope: products.read
  description: Grants read access to product data
  flows:
  - clientCredentials
  sources:
  - openapi/omnisend-batches-api-openapi.yml
  - openapi/omnisend-productcategories-api-openapi.yml
  - openapi/omnisend-products-api-openapi.yml
- scope: products.write
  description: Grants write access to product data
  flows:
  - clientCredentials
  sources:
  - openapi/omnisend-batches-api-openapi.yml
  - openapi/omnisend-productcategories-api-openapi.yml
  - openapi/omnisend-products-api-openapi.yml
- scope: segments.read
  description: Read segments
  flows:
  - clientCredentials
  sources:
  - openapi/omnisend-segments-api-openapi.yml
- scope: segments.write
  description: Create, update and delete segments
  flows:
  - clientCredentials
  sources:
  - openapi/omnisend-segments-api-openapi.yml
docs: https://api-docs.omnisend.com/reference/oauth
description: 'OAuth 2.0 scopes for Omnisend. The authoritative list is the provider''s own RFC 8414 authorization
  server metadata, which declares 26 scopes — six more than any OpenAPI contract exposes. The RFC 9728 protected-resource
  metadata on the MCP host declares a 22-scope subset: the four missing there (accounts.write, sessions.write, reports.read,
  brand-assets.write) are account-level scopes the MCP agent surface deliberately does not offer. Scope names are
  resource.action and map cleanly onto the API resources.'
authorization_server:
  issuer: https://app.omnisend.com
  metadata: https://mcp.omnisend.com/.well-known/oauth-authorization-server
  authorization_endpoint: https://app.omnisend.com/oauth2/authorize
  token_endpoint: https://app.omnisend.com/oauth2/token
  registration_endpoint: https://app.omnisend.com/oauth2/register
  revocation_endpoint: https://app.omnisend.com/oauth2/revoke
  grant_types:
  - authorization_code
  - refresh_token
  code_challenge_methods:
  - S256
  scope_delimiter: space
  note: Requested with the `scope` query parameter on the authorize call. Omnisend's OAuth page writes the parameter
    as `scopes` in its table and `scope` in its example — the RFC 6749 name is `scope`.
published_scopes:
- scope: contacts.write
  description: Create, update and delete contacts
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: contacts.read
  description: Read contacts
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: products.write
  description: Create, update and delete product data and categories
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: products.read
  description: Read product data
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: events.write
  description: Send customer events and declare custom event metadata
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: events.read
  description: Read customer events
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: accounts.write
  description: Account-level write. Not offered on the MCP surface.
  in_openapi: false
  on_mcp: false
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: sessions.write
  description: Session write. Not offered on the MCP surface.
  in_openapi: false
  on_mcp: false
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: brands.write
  description: Connect a store / write brand information (OAuth only)
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: brands.read
  description: Read brand information
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: automations.read
  description: Read automation workflows
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: automations.write
  description: Create, update, enable, disable and delete automation workflows
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: campaigns.read
  description: Read campaigns
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: campaigns.write
  description: Create, update, send, cancel, copy and delete campaigns
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: reports.read
  description: Read reports. Not offered on the MCP surface.
  in_openapi: false
  on_mcp: false
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: analytics.read
  description: Generate analytics reports and statistics
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: segments.read
  description: Read segments and segment statistics
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: segments.write
  description: Create, update and delete segments
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: email-templates.read
  description: Read email templates, email content and universal layouts
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: email-templates.write
  description: Create, update, delete and render email templates, content and universal layouts
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: images.read
  description: Read images
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: images.write
  description: Upload and delete images
  in_openapi: true
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: forms.read
  description: Read sign-up forms and form reports
  in_openapi: false
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: forms.write
  description: Create and update sign-up forms
  in_openapi: false
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: brand-assets.read
  description: Read brand assets
  in_openapi: false
  on_mcp: true
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
- scope: brand-assets.write
  description: Write brand assets. Not offered on the MCP surface.
  in_openapi: false
  on_mcp: false
  source: https://mcp.omnisend.com/.well-known/oauth-authorization-server
scope_count: 26
notes:
- The OpenAPI contracts declare only contacts.read and contacts.write inside the Bearer securityScheme; every other
  scope requirement is stated in prose in the per-operation description ("**Scopes:** `campaigns.write`"), not in
  the machine-readable security block.
- The Event Metadata API operations declare no scope in the spec at all — the derived entry "none" below is an artifact
  of that omission, not a claim that the operations are unauthenticated. The docs state events.write for create/update.
- forms.read / forms.write and brand-assets.* have no published OpenAPI at all; the Forms surface is reachable only
  through the MCP server.
- Client credentials are not self-serve — the OAuth page asks integrators to submit a Google Form and promises credentials
  in 1-3 business days. The MCP hosts advertise RFC 7591 dynamic client registration, which is a different and faster
  path.
- Access tokens are documented as effectively non-expiring (expires_in 9223372036) unless revoked.

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/omnisend-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.