Université de Montréal · OAuth Scopes

Université de Montréal OAuth Scopes

OAuth 2.0 probed

Université de Montréal uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

UniversityHigher EducationEducationCanadaQuébecFrench LanguageU15Public Research UniversityResearchResearch DataResearch ExpertiseIdentity FederationInstitutional RepositoryLibraryOpen AccessOAI-PMHShibbolethSAML
Scopes: 0 Flows: Method: probed

Scopes (0)

Université de Montréal implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.

Source

OAuth Scopes

Raw ↑
---
specification: API Commons Scopes
specificationVersion: '0.1'
provider: Université de Montréal
providerId: universite-de-montreal
generated: '2026-08-30'
method: probed
source: live probes of Université de Montréal surfaces, 2026-08-30
description: >-
  Authorization scopes across Université de Montréal's programmable surfaces. The institution
  publishes no OAuth 2.0 authorization server and therefore defines no OAuth scopes. What it does
  operate is a SAML attribute release policy through its Shibboleth IdP, which is the functional
  equivalent for the federated surfaces — and it is the only place where UdeM makes an
  access-control decision about a machine-readable identity.
oauth2:
  present: false
  detail: >-
    No authorization server, no token endpoint, no .well-known/oauth-authorization-server and no
    .well-known/openid-configuration were found on any umontreal.ca host. No scope vocabulary
    exists to record.
scopes: []
alternative_authorization:
- mechanism: SAML attribute release
  x-operator: institution
  surface: https://shibboleth.umontreal.ca/idp/shibboleth
  detail: >-
    The IdP declares an AttributeAuthorityDescriptor supporting SAML 1.1, meaning attribute
    queries are answered out of band as well as in the assertion. The scope asserted for released
    attributes is shibmd:Scope "umontreal.ca" — a service provider must reject any scoped
    attribute value from this IdP that does not carry that domain. The attribute release policy
    itself is not public; it is negotiated per service provider through the federation.
  evidence:
    url: https://shibboleth.umontreal.ca/idp/shibboleth
    status: 200
- mechanism: SADVR consent flags
  x-operator: institution
  surface: https://www.recherche.umontreal.ca/vitrine/rest/api/1.8/umontreal/info/individu
  detail: >-
    Not an authorization mechanism in the technical sense, but it is the only access constraint
    the SADVR API expresses. Each full individual record carries a `consentement` object naming
    the UdeM showcases the person agreed to appear in ("Vitrine de la recherche", "Répertoire des
    experts à l'intention des médias") with a `statutConsentement` flag, and an `affichageWeb`
    block giving the URLs where that consent applies. Each affiliation also carries `exclusion`
    and `exclusionTel` flags. The API returns the data regardless; honouring the flags is left
    entirely to the consumer.
  evidence:
    url: https://www.recherche.umontreal.ca/vitrine/rest/api/1.8/umontreal/info/individu?idsadvr=in13593
    status: 200
- mechanism: Dataverse API token
  x-operator: tenant
  surface: https://borealisdata.ca/api
  detail: >-
    Borealis issues per-account Dataverse API tokens with permissions derived from the Dataverse
    role model, not from a scope string. UdeM does not define or issue these.
notes: >-
  Recording an empty `scopes` list is the honest measurement here. It is not a gap in the probe —
  it is the finding.

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/universite-de-montreal-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.