Tower · OAuth Scopes
Tower OAuth Scopes
OAuth 2.0
searched
Tower publishes 53 OAuth 2.0 scopes. Scopes are the fine-grained permissions an application requests at authorization time to act against the Tower API on a user’s behalf.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
Data InfrastructureData EngineeringPythonApache IcebergLakehouseOrchestrationData PipelinesAI AgentsMCPETL
Scopes: 53
Flows:
Method: searched
Scopes (53)
| Scope | Description | Flows |
|---|---|---|
| api_keys | Access to all API key operations. | |
| api_keys:read | Read access for API keys. | |
| api_keys:create | Create access for API keys. | |
| api_keys:delete | Delete access for API keys. | |
| apps | Access to all apps operations. | |
| apps:read | Read access for apps. | |
| apps:run | Allows the API to run apps. | |
| apps:deploy | Allows the API key to be used to deploy a new app version. | |
| apps:create | Create access for apps. | |
| apps:update | Update access for apps (e.g. renaming app). | |
| apps:delete | Delete access for apps. | |
| catalogs | Access to all Tower catalog operations. | |
| catalogs:read | Read access for catalogs. | |
| catalogs:create | Create access for catalogs. | |
| catalogs:update | Update access for catalogs. | |
| catalogs:delete | Delete access for catalogs. | |
| catalogs:export | Export access for catalogs. | |
| envs | Access to all environment operations. | |
| envs:create | Create access for environments. | |
| envs:read | Read access for environments. | |
| envs:update | Update access for environments. | |
| notifications | Access to all notification operations. | |
| notifications:read | Read access for notifications. | |
| notifications:delete | Delete access for notifications. | |
| runs | Access to all run operations. | |
| runs:read | Read access for runs. | |
| runs:cancel | Allows for canceling an active run. | |
| runs:logs | Read access for run logs, including the stream of logs. | |
| runners | Access to all self-hosted runner operations. | |
| runners:read | Read access to runners. | |
| runners:credentials:create | Allows for creating credentials for self-hosted runners. | |
| sandbox | Access to all Tower sandbox operations. | |
| sandbox:secrets:create | Allows for creating a new secret in a sandbox. | |
| schedules | Access to all schedules operations. | |
| schedules:create | Create access for schedules. | |
| schedules:read | Read access for schedules. | |
| schedules:update | Update access for schedules. | |
| schedules:delete | Delete access for schedules. | |
| secrets | Access to all secrets operations. | |
| secrets:read | Read access for secrets. | |
| secrets:create | Create access for secrets. | |
| secrets:update | Update access for secrets. | |
| secrets:delete | Delete access for secrets. | |
| teams | Access to all team operations. | |
| teams:create | Create access for teams. | |
| teams:read | Read access for teams. | |
| teams:update | Update access for teams. | |
| teams:delete | Delete access for teams. | |
| webhooks | Access to all webhooks operations. | |
| webhooks:read | Read access for webhooks. | |
| webhooks:create | Create access for webhooks. | |
| webhooks:update | Update access for webhooks. | |
| webhooks:delete | Delete access for webhooks. |
📄 Provider scope reference: https://docs.tower.dev/docs/using-tower/api-keys