University of Helsinki · OAuth Scopes

University of Helsinki OAuth Scopes

OAuth 2.0 probed

University of Helsinki uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

EducationHigher EducationUniversityFinlandNordicResearchOpen DataResearch DataInstitutional RepositoryOAI-PMHIdentity FederationAPI GatewayCourse CatalogLibraryBiodiversity
Scopes: 0 Flows: Method: probed

Scopes (0)

University of Helsinki implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.

NO SCOPE STRINGS ARE PUBLISHED. This artifact records a measured absence, not an inventory. All thirteen institution-operated OpenAPI documents harvested from the University of Helsinki API portal and from api.laji.fi were parsed for `components.securitySchemes.*.flows.*.scopes` and the result was empty across every one of them. The single `oauth2` securityScheme in the estate (Course pages CMS) declares no flows at all, so there is nothing for a scope to hang from. Nothing here is inferred; no scope has been invented to fill the slot.

Source

OAuth Scopes

Raw ↑
generated: '2026-08-30'
method: probed
source: https://api.helsinki.fi/portal/environments/DEFAULT/configuration
x-operator: institution
note: >-
  NO SCOPE STRINGS ARE PUBLISHED. This artifact records a measured absence, not an inventory.
  All thirteen institution-operated OpenAPI documents harvested from the University of Helsinki
  API portal and from api.laji.fi were parsed for `components.securitySchemes.*.flows.*.scopes`
  and the result was empty across every one of them. The single `oauth2` securityScheme in the
  estate (Course pages CMS) declares no flows at all, so there is nothing for a scope to hang
  from. Nothing here is inferred; no scope has been invented to fill the slot.
authorization_model:
  kind: plan-subscription
  described_by: Gravitee API Management
  detail: >-
    Authorization at the University of Helsinki gateway is not expressed as OAuth scopes. It is
    expressed as a SUBSCRIPTION: an application is registered in the portal, subscribed to one
    named API, and granted one named plan on that API. The plan is the grant. Two APIs make this
    visible in their own specs — Helsinki.fi content declares two separate `X-Api-Key` schemes,
    `NewsApiKey` and `StudySearchApiKey`, described as "issued by the news plan" and "issued by
    the study search plan", which is plan-as-scope stated in the provider's own words.
  plan_security_enabled:
  - apikey
  - oauth2
  - jwt
  plan_security_disabled:
  - sharedApiKey
  - keyless
  evidence:
  - url: https://api.helsinki.fi/portal/environments/DEFAULT/configuration
    status: 200
    note: plan.security.{apikey,oauth2,jwt}.enabled true; sharedApiKey and keyless false.
  - url: https://api.helsinki.fi/portal/environments/DEFAULT/apis?size=200
    status: 200
    note: >-
      Fifteen public APIs listed. Per-API `plans` links exist on every entry but return 401
      without a portal session, so the plan names themselves are not publicly readable.
plan_endpoints_probed:
- url: https://api.helsinki.fi/portal/environments/DEFAULT/portal-information
  status: 401
  note: Authenticated-only; not readable anonymously.
scopes: []

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/university-of-helsinki-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.