Unico · OAuth Scopes

Unico OAuth Scopes

OAuth 2.0 searched

Unico uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

Identity VerificationBiometricsFacial RecognitionLiveness DetectionKYCFraud PreventionOnboardingAuthenticationAMLAge VerificationDocument VerificationIdentityBrazilLatin America
Scopes: 0 Flows: Method: searched

Scopes (0)

Unico implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.

Unico runs OAuth2 with the RFC 7523 JWT-bearer grant, but it does NOT publish a scope catalogue. The documented assertion carries a single wildcard scope claim, and authorization is expressed through the provisioned APIKEY (which capabilities the tenant's key enables) rather than through per-endpoint scopes. This is an honest record of that design, not a gap in our search: the Authentication page states the scope value verbatim and no permissions/scopes reference page exists anywhere in the developer.unico.io sitemap (184 URLs walked, 2026-09-02).

Source

OAuth Scopes

Raw ↑
generated: '2026-09-02'
method: searched
source: https://developer.unico.io/developers/api-reference/authentication
docs: https://developer.unico.io/developers/api-reference/authentication
note: >-
  Unico runs OAuth2 with the RFC 7523 JWT-bearer grant, but it does NOT publish a scope
  catalogue. The documented assertion carries a single wildcard scope claim, and
  authorization is expressed through the provisioned APIKEY (which capabilities the tenant's
  key enables) rather than through per-endpoint scopes. This is an honest record of that
  design, not a gap in our search: the Authentication page states the scope value verbatim
  and no permissions/scopes reference page exists anywhere in the developer.unico.io sitemap
  (184 URLs walked, 2026-09-02).
scheme: oauth2
grant_type: urn:ietf:params:oauth:grant-type:jwt-bearer
token_endpoint: https://identity.acesso.io/oauth2/token
scope_count: 1
scopes:
- name: '*'
  description: >-
    Wildcard scope asserted in the JWT `scope` claim. Documented verbatim as "grants all
    permissions" for the authenticated service account.
  source: https://developer.unico.io/developers/api-reference/authentication
authorization_model:
  granularity: tenant + api-key
  description: >-
    Effective permissions are bound to the APIKEY provisioned for the project, which selects
    the active product (Onboarding, Transactional, Cardholder Verification) and the capability
    recipe (flow) executed. Enabling a new capability requires Unico to reissue the key —
    the upgrade guide states this explicitly.
  evidence: https://developer.unico.io/developers/api-reference/api/upgrade-guide
per_endpoint_scopes_published: false

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/unico-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.