Stilla · OAuth Scopes

Stilla OAuth Scopes

OAuth 2.0 searched

Stilla publishes 4 OAuth 2.0 scopes via the authorizationCode and deviceCode flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the Stilla API on a user’s behalf.

Tokens are issued from https://login.stilla.ai/oauth2/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanyArtificial IntelligenceAI AgentsAgenticProductivityCollaborationMCPAutomationDeveloper ToolsEnterprise
Scopes: 4 Flows: authorizationCode, deviceCode Method: searched

OAuth endpoints

Authorization URL
https://login.stilla.ai/oauth2/authorize
Token URL
https://login.stilla.ai/oauth2/token
Flows
authorizationCodedeviceCode

Scopes (4)

ScopeDescriptionFlows
openid OpenID Connect authentication; issue an ID token. authorizationCode, deviceCode
profile Access the user's basic profile claims. authorizationCode, deviceCode
email Access the user's email address. authorizationCode, deviceCode
offline_access Issue a refresh token for long-lived access. authorizationCode, deviceCode

Source

OAuth Scopes

stilla-scopes.yml Raw ↑
generated: '2026-07-21'
method: searched
source: https://api.stilla.ai/.well-known/oauth-authorization-server
docs: https://login.stilla.ai/.well-known/openid-configuration
schemes:
  - name: OAuth2
    source: https://api.stilla.ai/.well-known/oauth-authorization-server
    issuer: https://login.stilla.ai
    flows:
      - flow: authorizationCode
        authorizationUrl: https://login.stilla.ai/oauth2/authorize
        tokenUrl: https://login.stilla.ai/oauth2/token
      - flow: deviceCode
        deviceAuthorizationUrl: https://login.stilla.ai/oauth2/device_authorization
        tokenUrl: https://login.stilla.ai/oauth2/token
scopes:
  - scope: openid
    description: OpenID Connect authentication; issue an ID token.
    flows: [authorizationCode, deviceCode]
  - scope: profile
    description: Access the user's basic profile claims.
    flows: [authorizationCode, deviceCode]
  - scope: email
    description: Access the user's email address.
    flows: [authorizationCode, deviceCode]
  - scope: offline_access
    description: Issue a refresh token for long-lived access.
    flows: [authorizationCode, deviceCode]
notes: >-
  Scopes are the standard OIDC set advertised by the WorkOS AuthKit authorization server
  (login.stilla.ai). The MCP protected-resource metadata declares an empty
  scopes_supported list, i.e. MCP access is authorized at the resource level rather than
  via granular API scopes. No product-specific permission scopes are published at the
  authorization-server level.