Documentation

Requesting Scopes

Choose the OAuth scopes your app asks for, and read which ones the token was actually granted.

Scopes are the permissions your app requests. The user sees them on the consent screen and can decline. Request the minimum your integration needs.

These are OAuth scopes, permissions on a token. They are unrelated to reward trigger scopes, which describe when a reward fires.

Requesting scopes

Pass a space-separated scope parameter to /authorize. You can also pass one on refresh to narrow it.

scope=openid profile activity:read reward:read

Your app can only request scopes it was granted at registration. The token response lists the scopes actually granted in its scope field. Use that list, not the one you asked for.

OpenID Connect scopes

  • openid: enables OIDC and returns an id_token.
  • profile, email: standard profile and email claims.
  • offline_access: requests a refresh token for long-lived access.

Resource scopes

Other scopes take the form resource:action, and some add a sub-resource (session:attendees:manage). Families include activity:*, session:*, membership:*, org:*, reward:*, profile:*, card:*, contact:* and wallet:*. Examples:

ScopeGrants
activity:readView activities
session:attendMark attendance / check in
membership:readView memberships
org:read, org:updateOrganization data and management
reward:read, reward:redeemView and redeem rewards
profile:readView profiles
user:readRead the user

Do not hard-code a scope list. Scope names are still being consolidated while v1 is in preview. The API Reference names the scope each endpoint requires, and that is the binding statement.

Sensitive scopes

A scope can be marked sensitive. The consent screen highlights it with an extra warning. org:delete and wallet:decrypt are examples.

Scope is necessary, not sufficient

For organization resources, the caller's role in the organization must also allow the action. A request with the right scope can still be refused, and the error says which side denied it. See Acting as an Organization.

The first time a user authorizes your app, Davi shows a consent screen listing the requested scopes, with sensitive ones called out separately. Later authorizations for the same scopes skip the prompt. Users can revoke your app from their Davi settings at any time.

For server-to-server calls with no user, see client credentials.

Next