Workday Business Processes · OAuth Scopes

Workday Business Processes OAuth Scopes

OAuth 2.0 searched

Workday Business Processes publishes 2 OAuth 2.0 scopes via the implicit flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Workday Business Processes API on a user’s behalf.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

Business ProcessesWorkflowsApprovalsHuman ResourcesEnterpriseSoftware-as-a-ServiceHCMFinancial ManagementProcess AutomationEvent StepsSOAPGraphQL
Scopes: 2 Flows: implicit Method: searched

OAuth endpoints

Authorization URL
https://{tenantAuthorizationHostname}/authorize https://auth.api.workday.com/v1/authorize
Flows
implicit

Scopes (2)

ScopeDescriptionFlows
read read custom business process types implicit
write modify custom business process types implicit

Source

OAuth Scopes

Raw ↑
generated: '2026-09-17'
method: searched
source: openapi/_original/workday-business-processes-business-process-v1-openapi.json + openapi/_original/workday-business-processes-custom-business-process-config-v1-openapi.json
docs: https://developer.workday.com/doc/zwx1518028675482.md
docs_note: Workday REST authorization is TWO-LAYERED and neither layer alone is enough. (1) OAuth scopes are selected when an API
  client is registered in the Developer Site Console; Workday calls them "scopes" but they are FUNCTIONAL AREAS, not the fine-grained
  read:x/write:x scopes most APIs publish, and the scope a given endpoint needs is stated in the endpoint description in the REST
  API Explorer rather than in a scopes reference page. (2) The tenant business process security policy still governs whether the
  authenticated security group may take the action. An agent holding a valid token can still be refused by policy.
schemes:
- name: OAuth2
  source: openapi/workday-business-processes-business-process-openapi.yml
  type: oauth2
  flows:
  - flow: implicit
    authorizationUrl: https://{tenantAuthorizationHostname}/authorize
    note: published as the literal <tenantAuthorizationHostname>; per-tenant
  declared_scopes: 0
  note: The businessProcess v1 spec declares an EMPTY scopes map. The real scope requirement is in each operation description —
    captured in operation_scopes[] below.
- name: oAuth2
  source: openapi/workday-business-processes-custom-business-process-config-openapi.yml
  type: oauth2
  description: Register an API Client
  flows:
  - flow: implicit
    authorizationUrl: https://auth.api.workday.com/v1/authorize
  declared_scopes: 2
documented_flows:
- flow: authorizationCode
  docs: https://developer.workday.com/doc/jzx1537909761291.md
- flow: clientCredentials
  docs: https://developer.workday.com/doc/axp1537909839739.md
- flow: refreshToken
  docs: https://developer.workday.com/doc/cqa1553122177664.md
scopes:
- scope: read
  description: read custom business process types
  flows:
  - implicit
  sources:
  - openapi/workday-business-processes-custom-business-process-config-openapi.yml
- scope: write
  description: modify custom business process types
  flows:
  - implicit
  sources:
  - openapi/workday-business-processes-custom-business-process-config-openapi.yml
functional_area_scopes:
- Adaptive Planning for Financial Plans
- Adaptive Planning for the Workforce
- Benefits
- Tenant Non-Configurable
operation_scopes:
- operation: GET /types
  functional_areas:
  - Tenant Non-Configurable
- operation: GET /types/{ID}
  functional_areas:
  - Tenant Non-Configurable
- operation: GET /types/{ID}/attachmentCategories
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: GET /eventSteps
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: POST /eventSteps/{ID}/questionnaire
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: POST /eventSteps/{ID}/reassign
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: POST /eventSteps/{ID}/deny
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: GET /eventSteps/{ID}
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: POST /eventSteps/{ID}/toDo
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: POST /eventSteps/{ID}/approve
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: POST /eventSteps/{ID}/sendBack
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: GET /events
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: GET /events/{ID}/remainingSteps
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: POST /events/{ID}/rescind
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: GET /events/{ID}/comments
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: GET /events/{ID}
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: GET /events/{ID}/inProgressSteps
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: POST /events/{ID}/cancel
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: GET /events/{ID}/attachments
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
- operation: GET /events/{ID}/completedSteps
  functional_areas:
  - Adaptive Planning for Financial Plans
  - Adaptive Planning for the Workforce
  - Benefits
  - Tenant Non-Configurable
gap:
  scopes_reference_page: false
  note: Workday publishes no scopes/permissions reference page for REST. The only machine-readable statement of scope per operation
    is the "Scope:" line embedded in each operation description, extracted above.

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/workday-business-processes-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.