Scopes

Scopes

Scopes in a REST API are a way to define permissions and ensure that applications only have access to the data they need. It is recommended to use the principle of least privileges to only grant an application the permissions it absolutely needs to function.

Defining scopes

The Revelation helpdesk API has a predefined set of scopes. When you create a new Client in the API dashboard you can assign the application limited scopes. For example, the revelation.api.user.read scope allows you to read (HTTP GET) user related data but does not allow you to make updates (HTTP POST). The revelation.api.client.manage scope allows you to read and update client related data and the revelation.api.ticket.all scope will allow you to read, update and delete ticket related data.

Here is a full list of current scopes available:

ScopeDescription
revelation.api.allAccess to all Revelation helpdesk API resources.
revelation.api.client.readAccess to read Revelation helpdesk API Client resources
revelation.api.client.manageAccess to READ / WRITE Revelation helpdesk API Client resources
revelation.api.client.allAccess to ALL Revelation helpdesk API Client resources
revelation.api.quicknote.readAccess to Read Revelation helpdesk API Quick Note resources
revelation.api.chat.allAccess to ALL Revelation helpdesk API Chat resources
revelation.api.user.readAccess to READ Revelation helpdesk API USER resources
revelation.api.user.manageAccess to READ / WRITE Revelation helpdesk API USER resources
revelation.api.user.allAccess to ALL Revelation helpdesk API USER resources
revelation.api.project.readAccess to Read Revelation helpdesk API Project resources
revelation.api.project.manageAccess to READ / WRITE Revelation helpdesk API Project resources
revelation.api.project.allAccess to ALL Revelation helpdesk API Project resources
revelation.api.sla.readAccess to Read Revelation helpdesk API SLA resources
revelation.api.ticket.readAccess to Read Revelation helpdesk API Ticket resources
revelation.api.ticket.manageAccess to READ / WRITE Revelation helpdesk API Ticket resources
revelation.api.ticket.allAccess to ALL Revelation helpdesk API Ticket resources
revelation.api.search.readAccess to Read Revelation helpdesk API Search resources
revelation.api.search.manageAccess to READ / WRITE Revelation helpdesk API Search resources
revelation.api.office.readAccess to Read Revelation helpdesk API Office resources
revelation.api.office.manageAccess to READ / WRITE Revelation helpdesk API Office resources
revelation.api.file.readAccess to Read Revelation helpdesk API File resources
revelation.api.file.manageAccess to READ / WRITE Revelation helpdesk API File resources
revelation.api.file.allAccess to ALL Revelation helpdesk API File resources
revelation.api.asset.readAccess to Read Revelation helpdesk API Asset resources
revelation.api.asset.manageAccess to READ / WRITE Revelation helpdesk API Asset resources
revelation.api.asset.allAccess to ALL Revelation helpdesk API Asset resources

  

OpenID Connect (OIDC) scopes

The Revelation helpdesk API uses some standard OIDC scopes to define what claims are returned in the access token. See below for details:

ScopeDescription
openid

This is the basic and required scope for OIDC. It is required when using the Authorization_Code grant type but is not supported in Client_Credentials grant_type.

See here for more details

profileProvides access to basic user profile information like the user's name, email and profile image
emailProvides the user's primary email address
rolesThe user role / access level
offline_accessAllows an application (client) to request a new access token on behalf of a user. Click here for more details.


Requesting scopes

When you create a new client application in the API dashboard, you have the option to add 1 or more ‘Allowed Scopes’ under the “Basics” tab. This allows you to define what claims are returned in the access token and restrict which permissions the application has when calling the API endpoints.

A screenshot of a computerDescription automatically generated

When you request a new access token from the Authorization server, you can include only the required scopes as long as it appears in the list of allowed scopes that were defined for that client.

In the example below we add scope=revelation.api.user.read  to allow only permission to read user data:

Code
curl -X POST "https://dev-win2019.revelationhelpdesk.com/Auth/113ec1d6-492d-41c0-81e1-9ba56a3e0ef8/connect/token" -H "Content-Type: application/x-www-form-urlencoded"  -d "scope=revelation.api.user.read&grant_type=client_credentials&client_id=dev-win2019&client_secret=9f1ffe16-0d65-5bff-d555-bc154e5dba1a"

 

If no scope parameter is specified, then the token will include all Allowed Scopes for that client. If a scope is not allowed or does not exist, the token request will return a 400 Bad Request error with { "error": "invalid_scope"}