Rill Data · OAuth Scopes

Rill Data OAuth Scopes

OAuth 2.0 searched

Rill Data publishes 1 OAuth 2.0 scope via the authorizationCode and deviceCode flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the Rill Data API on a user’s behalf.

Tokens are issued from https://admin.rilldata.com/auth/oauth/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanyAnalyticsBusiness IntelligenceDashboardsMetricsDataOLAPOpen SourceDeveloper Tools
Scopes: 1 Flows: authorizationCode, deviceCode Method: searched

OAuth endpoints

Authorization URL
https://admin.rilldata.com/auth/oauth/authorize
Token URL
https://admin.rilldata.com/auth/oauth/token
Flows
authorizationCodedeviceCode

Scopes (1)

ScopeDescriptionFlows
offline_access Issue a refresh token so the client (e.g. an MCP connector) can maintain long-lived access without re-authorizing. This is the only scope Rill's OAuth authorization server advertises as supported. authorizationCode, deviceCode

Source

OAuth Scopes

Raw ↑
generated: '2026-07-21'
method: searched
source: well-known/rill-data-oauth-authorization-server.json
docs: https://docs.rilldata.com/guide/ai/mcp
schemes:
  - name: OAuth2
    source: well-known/rill-data-oauth-authorization-server.json
    flows:
      - flow: authorizationCode
        authorizationUrl: https://admin.rilldata.com/auth/oauth/authorize
        tokenUrl: https://admin.rilldata.com/auth/oauth/token
        registrationUrl: https://admin.rilldata.com/auth/oauth/register
        pkce: S256
      - flow: deviceCode
        tokenUrl: https://admin.rilldata.com/auth/oauth/token
scopes:
  - scope: offline_access
    description: >-
      Issue a refresh token so the client (e.g. an MCP connector) can maintain
      long-lived access without re-authorizing. This is the only scope Rill's
      OAuth authorization server advertises as supported.
    flows: [authorizationCode, deviceCode]
    sources: [well-known/rill-data-oauth-authorization-server.json]
notes: >-
  Rill's OAuth authorization server advertises a single scope (offline_access);
  effective authorization is governed by the user's org/project roles rather
  than fine-grained OAuth scopes. Once authorized, data-plane access is scoped
  to the specific org/project/branch encoded in the MCP/runtime URL.