Zinnia · OAuth Scopes
Zinnia OAuth Scopes
OAuth 2.0
probed
Zinnia uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
InsuranceLife InsuranceAnnuitiesPolicy AdministrationInsurtechFinancial-ServicesThird Party AdministrationNew BusinessOrder EntryDocument-ManagementUnderwritingEnterprise
Scopes: 0
Flows:
Method: probed
Scopes (0)
Zinnia implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.
These are the OIDC identity scopes the Zinnia Auth0 tenant advertises, not API permissions. Zinnia carries API authorization in a custom claim - the Kong OpenID Connect plugin config in every published spec sets scopes_claim to "https://api.zinnia.io/permissions" (dev/qa/uat variants use the matching environment host) and requires an "aud" of the environment API host. The permission values themselves are issued per partner tenant and are not published, so the API-level scope list cannot be enumerated from public material.
These are the OIDC identity scopes the Zinnia Auth0 tenant advertises, not API permissions. Zinnia carries API authorization in a custom claim - the Kong OpenID Connect plugin config in every published spec sets scopes_claim to "https://api.zinnia.io/permissions" (dev/qa/uat variants use the matching environment host) and requires an "aud" of the environment API host. The permission values themselves are issued per partner tenant and are not published, so the API-level scope list cannot be enumerated from public material.
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.