scopes.ts

OAuth 2.0 scope configuration fields and template defaults.

config/scopes.ts exports a Record<string, { name: LocalizedText; description: LocalizedText; priority?: number }> object with one authorization scope per key. You can define your own scope keys. user and basic are template examples, not fixed fields. You can add, remove, or change keys, or export an empty object if there are no scopes.

The Scope union type exported at the end of the file is generated from the configuration object's keys. After changing scope keys, also update OAuth clients, upgrade rules, and other code or data that references those scopes.

Scope keys

Scope keys are nonempty strings that OAuth clients use when requesting authorization. They should be stable, recognizable English identifiers. Put the user-facing name in name.

Scope records

Each scope key maps to a record with the following format:

Prop

Type

Scopes specify which data or features an access token can access. They do not automatically include all of the user's roles or capabilities.

Template defaults

Scope keyname.valuedescription.valuepriority
userUser InformationAllows accessing user information.2
basicBasic AccessExample scope for basic product access.1

These two records only demonstrate the format. The template does not restrict scope keys to user and basic.