OnPay · OAuth Scopes
OnPay OAuth Scopes
OAuth 2.0
searched
OnPay publishes 6 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the OnPay API on a user’s behalf.
Tokens are issued from https://app.onpay.com/app/oauth/authorize.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
payrollhuman-resourcesemployee-benefitspayroll-taxsmall-businessworkforce-managementfintechhr-techtime-and-attendanceretirement-401k
Scopes: 6
Flows: authorizationCode
Method: searched
OAuth endpoints
Authorization URL
https://app.onpay.com/app/oauth/authorize
https://app.onpay.com/app/oauth/authorize
Token URL
https://app.onpay.com/app/oauth/authorize
https://app.onpay.com/app/oauth/authorize
Flows
authorizationCode
authorizationCode
Scopes (6)
| Scope | Description | Flows |
|---|---|---|
| Owner | OnPay company owner. Accepted on all 58 operations. | authorizationCode |
| Approver | Payroll approver. Accepted on all 58 operations, same reach as Owner in this spec. | authorizationCode |
| Controller | Restricted role. Accepted on 8 operations only — employee deduction reads, recent notes, termination and rehire, worksite reads, and pay-schedule dates. | authorizationCode |
| Manager | Restricted role. Accepted on the same 8 operations as Controller. | authorizationCode |
| Accountant | Declared in the securityScheme but required by ZERO operations in the published spec — an accountant-scoped token authorizes nothing the document describes. | authorizationCode |
| Employee | Self-service role. Accepted on 2 operations only — GET /employees/{employee_id}/deductions and GET /user. | authorizationCode |
📄 Provider scope reference: https://onpay.readme.io/reference/authorization