Developers
Menu

Ask only for what your app needs. People see every scope on the consent page.

Scopes decide what your app can do with a token. Ask for them in the scope parameter, separated by spaces:

scope=edits:read edits:write collections:read

Available scopes

ScopeWhat people see on the consent page
openidKnow who you are on Street Art Cities
profileSee your name, username and profile picture
emailSee your email address
edits:readSee the changes you've suggested
edits:writeSuggest changes to artworks and artists for you
edits:reviewAccept, reject and undo changes by others, if you're allowed to
collections:readSee your collections, including private ones
collections:writeCreate, change and delete your collections, and add artworks to them
markers:readSearch and look up artworks and other places on the map
artists:readSearch and look up artists and their artworks

openid, profile and email are for logging people in, see Log in with Street Art Cities.

Scopes don't add permissions

A scope only limits what your app can do. The person's own permissions still apply: with edits:review, your app can only review changes the person could review themselves on Street Art Cities. It's only meant for apps that help people review other people's changes; see Reviewing through the API.

If your app calls an endpoint without the right scope, you get a 403:

{ "error": "This app needs the edits:write scope to do that." }

Which endpoints need which scope

ScopeEndpoints
edits:readGET /api/edits/mine, GET /api/edits/:id, POST /api/edits/views
edits:writePOST /api/edits, POST /api/edits/evaluate-permissions
edits:reviewPOST /api/edits/:id/accept, /reject and /revert
collections:readGET endpoints of the Collections API, except GET /api/collections/:id, which anyone can use without a token
collections:writePOST and DELETE endpoints of the Collections API
markers:readAll endpoints of the Markers API
artists:readAll endpoints of the Artists API