Wyze · OAuth Scopes

Wyze OAuth Scopes

OAuth 2.0 searched

Wyze publishes 4 OAuth 2.0 scopes via the authorizationCode and refreshToken flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the Wyze API on a user’s behalf.

Tokens are issued from https://account.wyze.com/authentication/oauth/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanySmart HomeInternet of ThingsHome SecurityCamerasConsumer ElectronicsHome AutomationVideoSensorsCommerce
Scopes: 4 Flows: authorizationCode, refreshToken Method: searched

OAuth endpoints

Authorization URL
https://account.wyze.com/authentication/oauth/authorize
Token URL
https://account.wyze.com/authentication/oauth/token
Flows
authorizationCoderefreshToken

Scopes (4)

ScopeDescriptionFlows
openid Standard OpenID Connect scope; requests an ID token asserting the subject of the authenticated Wyze customer account. authorizationCode
email Releases the email and email_verified claims for the authenticated customer account. authorizationCode
customer-account-api:full Full access to the Shopify Customer Account API for the signed-in Wyze customer - orders, addresses, payment methods and profile. authorizationCode
customer-account-mcp-api:full Full access to the customer-account MCP surface at https://account.wyze.com/customer/api/mcp - order status, store credit balances and return requests on behalf of the signed-in customer. authorizationCode

Source

OAuth Scopes

wyze-scopes.yml Raw ↑
generated: '2026-08-02'
method: searched
source: https://www.wyze.com/.well-known/openid-configuration
file: well-known/wyze-openid-configuration.json
notes: >-
  Wyze publishes no OpenAPI, so no scopes could be derived from a spec. The scopes below
  are the complete scopes_supported list published in the OIDC discovery document served
  from the wyze.com origin for Shopify-backed Wyze customer accounts. The Wyze device
  /cloud API (api.wyzecam.com) is API-key + bearer-token based and has NO scope surface -
  it is intentionally absent here rather than represented with invented scopes.
schemes:
- name: WyzeCustomerAccountOIDC
  type: openIdConnect
  issuer: https://shopify.com/authentication/58004504738
  source: well-known/wyze-openid-configuration.json
  flows:
  - flow: authorizationCode
    authorizationUrl: https://account.wyze.com/authentication/oauth/authorize
    tokenUrl: https://account.wyze.com/authentication/oauth/token
    pkce: [S256]
  - flow: refreshToken
    tokenUrl: https://account.wyze.com/authentication/oauth/token
scopes:
- scope: openid
  description: >-
    Standard OpenID Connect scope; requests an ID token asserting the subject of the
    authenticated Wyze customer account.
  flows: [authorizationCode]
  sources: [well-known/wyze-openid-configuration.json]
- scope: email
  description: >-
    Releases the email and email_verified claims for the authenticated customer account.
  flows: [authorizationCode]
  sources: [well-known/wyze-openid-configuration.json]
- scope: customer-account-api:full
  description: >-
    Full access to the Shopify Customer Account API for the signed-in Wyze customer -
    orders, addresses, payment methods and profile.
  flows: [authorizationCode]
  sources: [well-known/wyze-openid-configuration.json]
- scope: customer-account-mcp-api:full
  description: >-
    Full access to the customer-account MCP surface at
    https://account.wyze.com/customer/api/mcp - order status, store credit balances and
    return requests on behalf of the signed-in customer.
  flows: [authorizationCode]
  sources: [well-known/wyze-openid-configuration.json]
claims_supported: [iss, sub, aud, exp, iat, nonce, sid, email, email_verified]