Scopes are the permissions your app requests. The user sees them on the consent screen and can decline. Request the minimum your integration needs.
These are OAuth scopes, permissions on a token. They are unrelated to reward trigger scopes, which describe when a reward fires.
Requesting scopes
Pass a space-separated scope parameter to /authorize. You can also pass one
on refresh to narrow it.
scope=openid profile activity:read reward:read
Your app can only request scopes it was granted at registration. The token
response lists the scopes actually granted in its scope field. Use that list,
not the one you asked for.
OpenID Connect scopes
openid: enables OIDC and returns anid_token.profile,email: standard profile and email claims.offline_access: requests a refresh token for long-lived access.
Resource scopes
Other scopes take the form resource:action, and some add a sub-resource
(session:attendees:manage). Families include activity:*, session:*,
membership:*, org:*, reward:*, profile:*, card:*, contact:* and
wallet:*. Examples:
| Scope | Grants |
|---|---|
activity:read | View activities |
session:attend | Mark attendance / check in |
membership:read | View memberships |
org:read, org:update | Organization data and management |
reward:read, reward:redeem | View and redeem rewards |
profile:read | View profiles |
user:read | Read the user |
Do not hard-code a scope list. Scope names are still being consolidated while
v1 is in preview. The API Reference names the scope each
endpoint requires, and that is the binding statement.
Sensitive scopes
A scope can be marked sensitive. The consent screen highlights it with an
extra warning. org:delete and wallet:decrypt are examples.
Scope is necessary, not sufficient
For organization resources, the caller's role in the organization must also allow the action. A request with the right scope can still be refused, and the error says which side denied it. See Acting as an Organization.
Consent
The first time a user authorizes your app, Davi shows a consent screen listing the requested scopes, with sensitive ones called out separately. Later authorizations for the same scopes skip the prompt. Users can revoke your app from their Davi settings at any time.
For server-to-server calls with no user, see client credentials.
Next
- Making Requests: call the API with your token.