Plotly · OAuth Scopes
Plotly OAuth Scopes
OAuth 2.0
probed
Plotly uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
CompanyData VisualizationAnalyticsData AppsBusiness IntelligenceOpen-SourcePythonJavaScriptChartsDashboardsDeveloper ToolsMCP
Scopes: 0
Flows: authorization_code, refresh_token, device_code, client_credentials
Method: probed
Scopes (0)
Plotly implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.
Read directly from the Plotly Cloud authorization server's own discovery documents (RFC 8414 and OpenID Connect Discovery), both fetched 2026-08-26. Plotly publishes no scopes reference page and declares no product- or resource-specific scopes: the advertised set is the standard OIDC quartet only. That is the finding - the Dash Docs MCP server is protected by authentication rather than by scoped authorization.
Read directly from the Plotly Cloud authorization server's own discovery documents (RFC 8414 and OpenID Connect Discovery), both fetched 2026-08-26. Plotly publishes no scopes reference page and declares no product- or resource-specific scopes: the advertised set is the standard OIDC quartet only. That is the finding - the Dash Docs MCP server is protected by authentication rather than by scoped authorization.
📄 Provider scope reference: https://dash.plotly.com/plotly-cloud/sign-in
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.