Toast · OAuth Scopes
Toast OAuth Scopes
OAuth 2.0
searched
Toast publishes 28 OAuth 2.0 scopes. Scopes are the fine-grained permissions an application requests at authorization time to act against the Toast API on a user’s behalf.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
Food ServicePoint-of-SaleRestaurantHospitality
Scopes: 28
Flows:
Method: searched
Scopes (28)
| Scope | Description | Flows |
|---|---|---|
| cashmgmt:read | Allows reading from the cash management API. | clientCredentials |
| config:read | Allows reading from the configuration API. | clientCredentials |
| credit_cards.authorization:write | Allows authorization of payments through the credit cards API. | clientCredentials |
| device-details.info:read | Allows reading from the device details API. | clientCredentials |
| kitchen:read | Allows reading from the kitchen API. | clientCredentials |
| labor:read | Allows reading all data except employees from the labor API. | clientCredentials |
| labor.employees:read | Allows reading employee information from the labor API. | clientCredentials |
| labor.employees:write | Allows updating employee information in the labor API. | clientCredentials |
| labor.jobs:write | Allows updating job information in the labor API. | clientCredentials |
| labor.shifts:write | Allows updating shift information in the labor API. | clientCredentials |
| menus.channel:read | Allows reading from the menus API V3. Ordering partner integrations must use V3, which requires this scope. | clientCredentials |
| menus:read | Allows reading from the menus API V2. Because V3 currently only supports ordering partner integrations, all other integration partners continue to use V2 with this scope. | clientCredentials |
| digital_schedule:read | Allows reading from the order management configuration API. | clientCredentials |
| orders:read | Allows reading from the orders API with the exception of guest information. If the API client creates orders, it must have BOTH orders:read and orders.channel:read to read them back. | clientCredentials |
| orders.channel:read | Allows API clients that submit orders to read from the orders API. Must be held together with orders:read. Clients with this scope can only read the orders they themselves created. | clientCredentials |
| delivery_info.address:read | Allows reading guest delivery address information from the orders API. | clientCredentials |
| guest.pi:read | Allows reading guest and curbside pickup information from the orders API. This is the scope that gates guest personal information. | clientCredentials |
| orders.delivery_info:write | Allows updating delivery information through the orders API. | clientCredentials |
| orders.discounts:write | Allows adding discounts to orders using the orders API. | clientCredentials |
| orders.items:write | Allows adding items to orders using the orders API. | clientCredentials |
| orders.orders:write | Allows posting orders using the orders API. | clientCredentials |
| orders.payments:write | Allows adding payments and tips to existing orders using the orders API. | clientCredentials |
| orders.channel:void | Allows voiding an order using the orders API. This is the only reversal scope Toast publishes. | clientCredentials |
| packaging:read | Allows reading a restaurant's packaging preferences configuration using the packaging configuration API. | clientCredentials |
| restaurants:read | Allows reading from the restaurant availability API and from the restaurants API. | clientCredentials |
| stock:read | Allows reading from the stock API. | clientCredentials |
| stock:write | Allows updating stock status for menu items and modifier option item references using the stock API. | clientCredentials |
| enterprise-metrics:read | Allows reading from the analytics API. Declared in the analytics OpenAPI securityScheme; not listed in the developer guide scope table, which covers the partner/custom integration scopes. | clientCredentials |
📄 Provider scope reference: https://doc.toasttab.com/doc/devguide/apiScopes.htmlhttps://doc.toasttab.com/doc/devguide/authentication.htmlhttps://doc.toasttab.com/doc/devguide/apiOrdersGetScopes.htmlhttps://doc.toasttab.com/doc/devguide/devApiAccessScopes.html
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.