Wawanesa Insurance · OAuth Scopes

Wawanesa Insurance OAuth Scopes

OAuth 2.0 searched

Wawanesa Insurance uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.

Tokens are issued from https://login.brokerplatform.wawanesa.com/oauth2/v1/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

InsuranceCanadaProperty and CasualtyCarrierMutual InsurerBrokerCommercial LinesPersonal LinesUnderwritingClaimsPolicy AdministrationCSIOPartner Gated
Scopes: 0 Flows: authorizationCode, clientCredentials Method: searched

OAuth endpoints

Authorization URL
https://login.brokerplatform.wawanesa.com/oauth2/v1/authorize https://brokerplatform.wawanesa.com/services/oauth2/authorize
Token URL
https://login.brokerplatform.wawanesa.com/oauth2/v1/token https://brokerplatform.wawanesa.com/services/oauth2/token
Flows
authorizationCodeclientCredentials

Scopes (0)

Wawanesa Insurance implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.

Wawanesa publishes no OpenAPI and no scope/permission reference, so there is no insurance-business scope vocabulary to harvest. Every scope below was read verbatim from the `scopes_supported` array of a live discovery document on a Wawanesa host. They are STOCK IDENTITY-PLATFORM scopes — standard OIDC claims scopes on the Okta broker issuer, Okta org-management scopes on the Okta org authorization server, and stock Salesforce Experience Cloud platform scopes on the Broker Platform. None of them grants access to a quote, bind, policy, billing or claims capability; they govern broker sign-in and the vendor platforms underneath it. Recorded here so the gap is explicit rather than implied. Wawanesa's real API authorization model is defined by CSIO's API Security Standards (certified 2024-10-29), which is member-gated and does not publish its scope vocabulary publicly.

Source

OAuth Scopes

wawanesa-scopes.yml Raw ↑
generated: '2026-07-25'
method: searched
source: >-
  live anonymous fetch of the OAuth 2.0 / OpenID Connect discovery documents on
  the Wawanesa Broker Platform hosts (2026-07-25)
docs: null
note: >-
  Wawanesa publishes no OpenAPI and no scope/permission reference, so there is
  no insurance-business scope vocabulary to harvest. Every scope below was read
  verbatim from the `scopes_supported` array of a live discovery document on a
  Wawanesa host. They are STOCK IDENTITY-PLATFORM scopes — standard OIDC claims
  scopes on the Okta broker issuer, Okta org-management scopes on the Okta org
  authorization server, and stock Salesforce Experience Cloud platform scopes on
  the Broker Platform. None of them grants access to a quote, bind, policy,
  billing or claims capability; they govern broker sign-in and the vendor
  platforms underneath it. Recorded here so the gap is explicit rather than
  implied. Wawanesa's real API authorization model is defined by CSIO's API
  Security Standards (certified 2024-10-29), which is member-gated and does not
  publish its scope vocabulary publicly.
schemes:
- name: BrokerPlatformOkta
  source: well-known/wawanesa-brokerplatform-login-openid-configuration.json
  kind: openid-connect
  flows:
  - flow: authorizationCode
    authorizationUrl: https://login.brokerplatform.wawanesa.com/oauth2/v1/authorize
    tokenUrl: https://login.brokerplatform.wawanesa.com/oauth2/v1/token
- name: BrokerPlatformOktaOrgAuthorizationServer
  source: well-known/wawanesa-brokerplatform-login-oauth-authorization-server.json
  kind: oauth2
  flows:
  - flow: clientCredentials
    tokenUrl: https://login.brokerplatform.wawanesa.com/oauth2/v1/token
  - flow: authorizationCode
    authorizationUrl: https://login.brokerplatform.wawanesa.com/oauth2/v1/authorize
    tokenUrl: https://login.brokerplatform.wawanesa.com/oauth2/v1/token
- name: BrokerPlatformSalesforce
  source: well-known/wawanesa-brokerplatform-openid-configuration.json
  kind: openid-connect
  flows:
  - flow: authorizationCode
    authorizationUrl: https://brokerplatform.wawanesa.com/services/oauth2/authorize
    tokenUrl: https://brokerplatform.wawanesa.com/services/oauth2/token
scope_groups:
- group: oidc-standard
  class: identity
  description: Standard OpenID Connect scopes advertised by the Okta broker issuer.
  schemes: [BrokerPlatformOkta]
  scopes:
  - {scope: openid, description: OpenID Connect authentication}
  - {scope: profile, description: Basic profile claims}
  - {scope: email, description: Email address claim}
  - {scope: address, description: Address claim}
  - {scope: phone, description: Phone number claim}
  - {scope: groups, description: Group membership claims}
  - {scope: offline_access, description: Refresh-token issuance}
- group: okta-org-management
  class: vendor-platform
  description: >-
    Okta org-administration scopes advertised by the RFC 8414 authorization
    server metadata. These administer the identity tenant itself, not insurance
    data.
  schemes: [BrokerPlatformOktaOrgAuthorizationServer]
  scope_count: 76
  scopes:
  - okta.accessRequests.tasks.manage
  - okta.accessRequests.tasks.read
  - okta.agentPools.manage
  - okta.agentPools.read
  - okta.apiTokens.manage
  - okta.apiTokens.read
  - okta.appGrants.manage
  - okta.appGrants.read
  - okta.apps.manage
  - okta.apps.read
  - okta.behaviors.manage
  - okta.behaviors.read
  - okta.brands.manage
  - okta.brands.read
  - okta.certificateAuthorities.manage
  - okta.certificateAuthorities.read
  - okta.clients.manage
  - okta.clients.read
  - okta.clients.register
  - okta.directories.groups.manage
  - okta.directories.manage
  - okta.domains.manage
  - okta.domains.read
  - okta.eventHooks.manage
  - okta.eventHooks.read
  - okta.events.read
  - okta.factors.manage
  - okta.factors.read
  - okta.features.manage
  - okta.features.read
  - okta.governance.assignmentCandidates.read
  - okta.groups.manage
  - okta.groups.read
  - okta.idps.manage
  - okta.idps.read
  - okta.inlineHooks.manage
  - okta.inlineHooks.read
  - okta.linkedObjects.manage
  - okta.linkedObjects.read
  - okta.logs.read
  - okta.networkZones.manage
  - okta.networkZones.read
  - okta.orgs.manage
  - okta.orgs.read
  - okta.personal.adminSettings.manage
  - okta.personal.adminSettings.read
  - okta.policies.manage
  - okta.policies.read
  - okta.principalRateLimits.manage
  - okta.principalRateLimits.read
  - okta.profileMappings.manage
  - okta.profileMappings.read
  - okta.rateLimits.manage
  - okta.rateLimits.read
  - okta.reports.manage
  - okta.reports.read
  - okta.riskProviders.manage
  - okta.riskProviders.read
  - okta.roles.manage
  - okta.roles.read
  - okta.schemas.manage
  - okta.schemas.read
  - okta.sessions.manage
  - okta.sessions.read
  - okta.templates.manage
  - okta.templates.read
  - okta.threatInsights.manage
  - okta.threatInsights.read
  - okta.trustedOrigins.manage
  - okta.trustedOrigins.read
  - okta.userTypes.manage
  - okta.userTypes.read
  - okta.users.manage
  - okta.users.manage.self
  - okta.users.read
  - okta.users.read.self
- group: salesforce-platform
  class: vendor-platform
  description: >-
    Stock Salesforce Experience Cloud scopes advertised by the Broker Platform
    OIDC document. Generic platform capabilities (API access, Chatter, Data
    Cloud, Einstein), not Wawanesa insurance permissions.
  schemes: [BrokerPlatformSalesforce]
  scope_count: 36
  scopes:
  - address
  - api
  - cdp_api
  - cdp_calculated_insight_api
  - cdp_identityresolution_api
  - cdp_ingest_api
  - cdp_profile_api
  - cdp_query_api
  - cdp_segment_api
  - chatbot_api
  - chatter_api
  - content
  - custom_permissions
  - data_cloud_user_claims
  - eclair_api
  - einstein_gpt_api
  - email
  - forgot_password
  - full
  - id
  - interaction_api
  - lightning
  - mcp_api
  - offline_access
  - openid
  - pardot_api
  - phone
  - profile
  - pwdless_login_api
  - refresh_token
  - scrt_api
  - sfap_api
  - user_registration_api
  - visualforce
  - wave_api
  - web
business_scopes:
  published: false
  note: >-
    No quote/bind/policy/billing/claims scope vocabulary is published by
    Wawanesa or reachable anonymously. Insurance-capability authorization is
    governed by CSIO's API Security Standards inside the broker channel.
related:
  authentication: authentication/wawanesa-authentication.yml
  well_known: well-known/wawanesa-well-known.yml