Wato · OAuth Scopes

Wato OAuth Scopes

OAuth 2.0 searched

Wato publishes 4 OAuth 2.0 scopes via the authorizationCode and deviceCode flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the Wato API on a user’s behalf.

Tokens are issued from https://qualified-tree-19-staging.authkit.app/oauth2/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanyMCPModel Context ProtocolAI AgentsAgent GovernanceTeam MemoryConnectorsAgent SkillsAutomationDeveloper ToolsY Combinator
Scopes: 4 Flows: authorizationCode, deviceCode Method: searched

OAuth endpoints

Authorization URL
https://qualified-tree-19-staging.authkit.app/oauth2/authorize
Token URL
https://qualified-tree-19-staging.authkit.app/oauth2/token
Flows
authorizationCodedeviceCode

Scopes (4)

ScopeDescriptionFlows
openid OpenID Connect authentication (ID token issuance) authorizationCode, deviceCode
profile Access to the user's basic profile claims authorizationCode, deviceCode
email Access to the user's email address claim authorizationCode, deviceCode
offline_access Issue a refresh token for long-lived MCP client sessions authorizationCode, deviceCode

Source

OAuth Scopes

wato-scopes.yml Raw ↑
generated: '2026-07-21'
method: searched
source: https://mesh.watolabs.com/.well-known/oauth-authorization-server
docs: https://docs.watolabs.com/docs/connect-clients
notes: >-
  Scopes published as scopes_supported in the authorization server's RFC 8414
  metadata (WorkOS AuthKit). These are identity/OIDC scopes — Wato does not
  publish fine-grained API scopes; tool- and memory-level access is governed
  server-side per team, role, and connector approval rather than via OAuth
  scope strings (see conventions/wato-conventions.yml).
schemes:
- name: watoOAuth
  source: well-known/wato-oauth-authorization-server.json
  flows:
  - flow: authorizationCode
    authorizationUrl: https://qualified-tree-19-staging.authkit.app/oauth2/authorize
    tokenUrl: https://qualified-tree-19-staging.authkit.app/oauth2/token
  - flow: deviceCode
    deviceAuthorizationUrl: https://qualified-tree-19-staging.authkit.app/oauth2/device_authorization
    tokenUrl: https://qualified-tree-19-staging.authkit.app/oauth2/token
scopes:
- scope: openid
  description: OpenID Connect authentication (ID token issuance)
  flows: [authorizationCode, deviceCode]
- scope: profile
  description: Access to the user's basic profile claims
  flows: [authorizationCode, deviceCode]
- scope: email
  description: Access to the user's email address claim
  flows: [authorizationCode, deviceCode]
- scope: offline_access
  description: Issue a refresh token for long-lived MCP client sessions
  flows: [authorizationCode, deviceCode]