TwentyCi · OAuth Scopes

TwentyCi OAuth Scopes

OAuth 2.0 derived

TwentyCi publishes 1 OAuth 2.0 scope via the password flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the TwentyCi API on a user’s behalf.

Tokens are issued from https://api.twentyci.co.uk/oauth/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

Real EstateUnited KingdomPropTechProperty DataValuationAVMRentalsAddress DataConveyancingHomemover DataAgent PerformanceData as a Service
Scopes: 1 Flows: password Method: derived

OAuth endpoints

Token URL
https://api.twentyci.co.uk/oauth/token
Flows
password

Scopes (1)

ScopeDescriptionFlows
* Full access; the only scope value documented by TwentyCi. password

Source

OAuth Scopes

Raw ↑
generated: '2026-07-26'
method: derived
source: openapi/twentyci-twentyapi-openapi.json
schemes:
- name: twentyapiOAuth
  source: openapi/twentyci-twentyapi-openapi.json
  flows:
  - flow: password
    tokenUrl: https://api.twentyci.co.uk/oauth/token
  description: 'OAuth 2.0 bearer token. TwentyCi''s documentation labels the scheme "OAuth2"
    with flow "Implicit" but describes a resource-owner password-credentials exchange: POST
    /oauth/token with client_id, client_secret, username, password, grant_type=password and
    scope=* returns {token_type: Bearer, expires_in, access_token, refresh_token}. The token
    is then sent as "Authorization: Bearer <token-key>". Modelled here as the password flow
    because that is what the documented request body performs. No OpenID Connect discovery document
    is served (/.well-known/openid-configuration returned 404).'
scopes:
- scope: '*'
  description: Full access; the only scope value documented by TwentyCi.
  flows:
  - password
  sources:
  - openapi/twentyci-twentyapi-openapi.json