University of California, San Diego OAuth Scopes

OAuth 2.0 probed

University of California, San Diego uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

EducationHigher EducationUniversityPublic Research UniversityUC SystemUnited StatesCaliforniaResearchResearch DataDigital CollectionsIdentity FederationAPI GatewayArtificial IntelligenceResearch Computing
Scopes: 0 Flows: Method: probed

Scopes (0)

University of California, San Diego implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.

Source

OAuth Scopes

Raw ↑
generated: '2026-08-19'
method: probed
source: >-
  https://api.ucsd.edu/api/am/devportal/v2/settings (200, anonymous) and
  https://tritonai-api.ucsd.edu/openapi.json (200)
provider: University of California, San Diego
providerId: ucsd
description: >-
  Authorization scopes observable on UC San Diego's institution-operated API surfaces. Both
  surfaces are credential-gated; the scope names below were read from endpoints that answer
  anonymously, not from published developer documentation, because UC San Diego does not
  publish a scope reference outside its Single Sign-On boundary.
surfaces:
  - name: UC San Diego API Gateway (WSO2 API Manager 4.1.0)
    host: api.ucsd.edu
    x-operator: institution
    model: OAuth 2.0 / OpenID Connect scopes issued by the gateway's own key manager
    evidence:
      url: https://api.ucsd.edu/api/am/devportal/v2/settings
      status: 200
    notes: >-
      The gateway reports IsAnonymousModeEnabled=false, monetizationEnabled=false and
      identityProvider.external=false, which is why the API catalogue itself
      (/api/am/devportal/v2/apis) answers 401 to an unauthenticated client. The scope names are
      WSO2 product scopes governing developer-portal actions, not per-API business scopes; the
      per-API scopes are behind the same 401.
    scopes:
      - name: apim:admin
        description: Administrative access to the developer portal.
      - name: apim:api_key
        description: Issue and manage API keys for a subscribed application.
      - name: apim:app_import_export
        description: Import and export developer-portal applications.
      - name: apim:app_manage
        description: Create, update and delete developer-portal applications.
      - name: apim:store_settings
        description: Read developer-portal settings.
      - name: apim:sub_alert_manage
        description: Manage subscriber alert configuration.
      - name: apim:sub_manage
        description: Manage subscriptions to published APIs.
      - name: apim:subscribe
        description: Subscribe an application to a published API.
      - name: openid
        description: OpenID Connect identity scope.
  - name: TritonAI Developer API (LiteLLM Gateway)
    host: tritonai-api.ucsd.edu
    x-operator: institution
    model: Bearer token — issued TritonAI API key
    evidence:
      url: https://tritonai-api.ucsd.edu/openapi.json
      status: 200
    notes: >-
      The gateway declares no OAuth scope vocabulary. Authorization is a single opaque
      credential; entitlement is expressed server-side through LiteLLM key, team, budget and
      access-group objects rather than through scopes on the wire. Access is granted to approved
      UC San Diego faculty, staff, researchers and campus teams.
    scopes: []
  - name: UC San Diego Library Digital Collections JSON API
    host: library.ucsd.edu
    x-operator: institution
    model: none — anonymous read
    evidence:
      url: https://library.ucsd.edu/dc/search.json?q=ocean
      status: 200
    notes: >-
      No authorization layer. Entitlement is enforced server-side by a fixed Solr filter query
      (discover_access_group_ssim:public OR discover_access_group_ssim:unknown), so restricted
      and embargoed material is never returned to an anonymous client.
    scopes: []

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/ucsd-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.