Secureframe · OAuth Scopes
Secureframe OAuth Scopes
OAuth 2.0
probed
Secureframe uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
GRCComplianceSOC 2ISO 27001RiskCMMCFedRAMPSecurityAuditTrust
Scopes: 0
Flows:
Method: probed
Scopes (0)
Secureframe implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.
A single scope named "mcp" grants the whole surface. There is no read-only scope, no per-resource scope and no way to grant an agent a subset — even though the provider labels 63 of its 112 tools read and 49 write. Effective permissions are whatever the authorizing user's RBAC role allows, which the agent cannot enumerate through the API.
A single scope named "mcp" grants the whole surface. There is no read-only scope, no per-resource scope and no way to grant an agent a subset — even though the provider labels 63 of its 112 tools read and 49 write. Effective permissions are whatever the authorizing user's RBAC role allows, which the agent cannot enumerate through the API.
📄 Provider scope reference: https://mcp.secureframe.com/mcp_docs
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.