University of Maryland College Park OAuth Scopes

OAuth 2.0 probed

University of Maryland College Park uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

UniversityHigher EducationEducationUnited StatesMarylandPublic Research UniversityLand GrantBig TenLibraryResearch DataDigital CollectionsIdentity FederationOAI-PMHOpen DataGeospatial
Scopes: 0 Flows: Method: probed

Scopes (0)

University of Maryland College Park implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.

Source

OAuth Scopes

Raw ↑
generated: '2026-08-30'
method: probed
source: live requests plus the OpenAPI at https://api.www.lib.umd.edu/api/libtools/openapi.json
x-operator: institution
provider: University of Maryland College Park
providerId: university-of-maryland-college-park
description: >-
  Scope inventory for the University of Maryland's institution-operated API surfaces. There are
  no scopes to inventory. The library and repository surfaces are keyless and read-only, so
  authorisation there is all-or-nothing at the endpoint rather than partitioned by scope; the one
  credentialed surface, the campus Enterprise GIS, gates access with an ArcGIS token whose privileges
  come from a UMD Portal account role, which is not a scope either. This record exists so the absence
  is a measured finding rather than an untested assumption.
scopes: []
findings:
- surface: UMD Libraries Website Tools API
  scopes_declared: 0
  reason: no_auth
  detail: >-
    No securitySchemes in the contract and no credential accepted or required on any of the 13
    GET operations.
- surface: OAI-PMH endpoints (fcrepo, av, archives)
  scopes_declared: 0
  reason: protocol_has_no_scopes
  detail: >-
    OAI-PMH 2.0 partitions harvesting by setSpec, not by authorisation scope. ListSets is open
    on all three endpoints.
- surface: UMD Enterprise GIS — ArcGIS REST Services
  scopes_declared: 0
  reason: token_not_scoped
  detail: >-
    ArcGIS Server tokens carry the privileges of the Portal account that requested them; there is no
    scope parameter on generateToken and no per-service scope vocabulary to enumerate. The service
    catalog root is readable with no token at all, and every folder beneath it returns error 499.
- surface: UMD Shibboleth Identity Provider
  scopes_declared: 0
  reason: not_an_oauth_server
  detail: >-
    SAML 2.0 releases attributes under entity categories, not OAuth scopes. UMD asserts the
    InCommon and REFEDS Research and Scholarship categories, which govern attribute release to
    federated service providers rather than API authorisation.

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/university-of-maryland-college-park-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.