Unit · OAuth Scopes

Unit OAuth Scopes

OAuth 2.0 searched

Unit publishes 46 OAuth 2.0 scopes. Scopes are the fine-grained permissions an application requests at authorization time to act against the Unit API on a user’s behalf.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

FintechBackend-as-a-ServiceBankingPaymentsCard IssuingACHLendingJSON:API
Scopes: 46 Flows: Method: searched

Scopes (46)

ScopeDescriptionFlows
applications
applications-write
customer-token
customer-token-write
customers
customers-write
customer-tags-write
accounts
accounts-write
cards
cards-write
cards-sensitive
cards-sensitive-write
transactions
transactions-write
authorizations
statements
payments
payments-write
payments-write-counterparty
payments-write-linked-account
payments-write-ach-debit
ach-payments-write
wire-payments-write
counterparties
counterparties-write
events
events-write
webhooks
webhooks-write
authorization-requests
authorization-requests-write
batch-releases
batch-releases-write
check-deposits
check-deposits-write
check-payments
check-payments-write
received-payments
received-payments-write
chargebacks
chargebacks-write
rewards
rewards-write
wire-drawdowns
wire-drawdowns-write

Source

OAuth Scopes

Raw ↑
generated: '2026-07-23'
method: searched
source: https://www.unit.co/docs/api/using-the-api
docs: https://www.unit.co/docs/api/using-the-api#scopes
note: >-
  Unit authenticates with OAuth 2.0 Bearer tokens (Org API tokens and short-lived
  Customer tokens). Each token is minted with a set of scopes granting read/write
  access per resource. The OpenAPI declares the transport as http bearer (JWT); the
  scope catalog below is documented in the "Scopes" section of the docs, not in the
  spec's securitySchemes. Fund-movement and PCI-sensitive scopes require Two-Factor
  Authentication (OTP) within the prior 24 hours; Customer tokens execute the 2FA for you.
token_types:
  - name: Org API token
    role: org
    description: Broad, system-level token not restricted to a specific end customer.
  - name: Customer token
    role: customer
    description: >-
      End-customer specific, scoped to a single customer's resources, with built-in
      OTP 2FA and a customizable expiry up to 24 hours. Required for PCI-sensitive
      card data/actions unless the client is PCI Level 1 compliant.
scopes:
  - {scope: applications, access: read, resource: Application, accessible_using: [org]}
  - {scope: applications-write, access: write, resource: Application, accessible_using: [org]}
  - {scope: customer-token, access: read, resource: Customer Token, accessible_using: [org]}
  - {scope: customer-token-write, access: write, resource: Customer Token, accessible_using: [org]}
  - {scope: customers, access: read, resource: Customers, accessible_using: [org, customer]}
  - {scope: customers-write, access: write, resource: Customers, accessible_using: [org, customer]}
  - {scope: customer-tags-write, access: write, resource: Customer Tags, accessible_using: [org, customer]}
  - {scope: accounts, access: read, resource: Accounts, accessible_using: [org, customer]}
  - {scope: accounts-write, access: write, resource: Accounts, accessible_using: [org, customer], note: "Close Account requires Org API token"}
  - {scope: cards, access: read, resource: Cards, accessible_using: [org, customer]}
  - {scope: cards-write, access: write, resource: Cards, accessible_using: [org, customer]}
  - {scope: cards-sensitive, access: read, resource: Cards Sensitive, accessible_using: [customer], sensitive: pci}
  - {scope: cards-sensitive-write, access: write, resource: Cards Sensitive, accessible_using: [customer], sensitive: pci}
  - {scope: transactions, access: read, resource: Transactions, accessible_using: [org, customer]}
  - {scope: transactions-write, access: write, resource: Transactions, accessible_using: [org, customer]}
  - {scope: authorizations, access: read, resource: Authorizations, accessible_using: [org, customer]}
  - {scope: statements, access: read, resource: Statements, accessible_using: [org, customer]}
  - {scope: payments, access: read, resource: Payments, accessible_using: [org, customer]}
  - {scope: payments-write, access: write, resource: Payments, accessible_using: [org, customer], sensitive: funds}
  - {scope: payments-write-counterparty, access: write, resource: Payments to a counterparty, accessible_using: [org, customer], sensitive: funds}
  - {scope: payments-write-linked-account, access: write, resource: Payments to a linked account, accessible_using: [org, customer], sensitive: funds}
  - {scope: payments-write-ach-debit, access: write, resource: Payments ACH Debit, accessible_using: [org, customer], sensitive: funds}
  - {scope: ach-payments-write, access: write, resource: Payments ACH, accessible_using: [org, customer], sensitive: funds}
  - {scope: wire-payments-write, access: write, resource: Payments Wire, accessible_using: [org, customer], sensitive: funds}
  - {scope: counterparties, access: read, resource: Counterparties, accessible_using: [org, customer]}
  - {scope: counterparties-write, access: write, resource: Counterparties, accessible_using: [org, customer]}
  - {scope: events, access: read, resource: Events, accessible_using: [org, customer]}
  - {scope: events-write, access: write, resource: Events, accessible_using: [org, customer]}
  - {scope: webhooks, access: read, resource: Webhooks, accessible_using: [org]}
  - {scope: webhooks-write, access: write, resource: Webhooks, accessible_using: [org]}
  - {scope: authorization-requests, access: read, resource: Authorization Requests, accessible_using: [org]}
  - {scope: authorization-requests-write, access: write, resource: Authorization Requests, accessible_using: [org]}
  - {scope: batch-releases, access: read, resource: Batch Releases, accessible_using: [org]}
  - {scope: batch-releases-write, access: write, resource: Batch Releases, accessible_using: [org]}
  - {scope: check-deposits, access: read, resource: Check Deposits, accessible_using: [org, customer]}
  - {scope: check-deposits-write, access: write, resource: Check Deposits, accessible_using: [org, customer]}
  - {scope: check-payments, access: read, resource: Check Payments, accessible_using: [org, customer]}
  - {scope: check-payments-write, access: write, resource: Check Payments, accessible_using: [org, customer]}
  - {scope: received-payments, access: read, resource: Received Payment, accessible_using: [org]}
  - {scope: received-payments-write, access: write, resource: Received Payment, accessible_using: [org]}
  - {scope: chargebacks, access: read, resource: Chargeback, accessible_using: [org]}
  - {scope: chargebacks-write, access: write, resource: Chargeback, accessible_using: [org]}
  - {scope: rewards, access: read, resource: Reward, accessible_using: [org]}
  - {scope: rewards-write, access: write, resource: Reward, accessible_using: [org]}
  - {scope: wire-drawdowns, access: read, resource: Wire Drawdowns, accessible_using: [org, customer]}
  - {scope: wire-drawdowns-write, access: write, resource: Wire Drawdowns, accessible_using: [org, customer]}

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/unit-co-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.