Scopes decide what your app can do with a token. Ask for them in the scope parameter, separated by spaces:
scope=edits:read edits:write collections:readAvailable scopes
| Scope | What people see on the consent page |
|---|---|
openid | Know who you are on Street Art Cities |
profile | See your name, username and profile picture |
email | See your email address |
edits:read | See the changes you've suggested |
edits:write | Suggest changes to artworks and artists for you |
edits:review | Accept, reject and undo changes by others, if you're allowed to |
collections:read | See your collections, including private ones |
collections:write | Create, change and delete your collections, and add artworks to them |
markers:read | Search and look up artworks and other places on the map |
artists:read | Search and look up artists and their artworks |
openid, profile and email are for logging people in, see Log in with Street Art Cities.
Scopes don't add permissions
A scope only limits what your app can do. The person's own permissions still apply: with edits:review, your app can only review changes the person could review themselves on Street Art Cities. It's only meant for apps that help people review other people's changes; see Reviewing through the API.
If your app calls an endpoint without the right scope, you get a 403:
{ "error": "This app needs the edits:write scope to do that." }Which endpoints need which scope
| Scope | Endpoints |
|---|---|
edits:read | GET /api/edits/mine, GET /api/edits/:id, POST /api/edits/views |
edits:write | POST /api/edits, POST /api/edits/evaluate-permissions |
edits:review | POST /api/edits/:id/accept, /reject and /revert |
collections:read | GET endpoints of the Collections API, except GET /api/collections/:id, which anyone can use without a token |
collections:write | POST and DELETE endpoints of the Collections API |
markers:read | All endpoints of the Markers API |
artists:read | All endpoints of the Artists API |