# Scopes

Ask only for what your app needs. People see every scope on the consent page.

Scopes decide what your app can do with a token. Ask for them in the `scope` parameter, separated by spaces:

```text
scope=edits:read edits:write collections:read
```

## Available scopes

| Scope               | What people see on the consent page                                  |
| ------------------- | -------------------------------------------------------------------- |
| `openid`            | Know who you are on Street Art Cities                                |
| `profile`           | See your name, username and profile picture                          |
| `email`             | See your email address                                               |
| `edits:read`        | See the changes you've suggested                                     |
| `edits:write`       | Suggest changes to artworks and artists for you                      |
| `edits:review`      | Accept, reject and undo changes by others, if you're allowed to      |
| `collections:read`  | See your collections, including private ones                         |
| `collections:write` | Create, change and delete your collections, and add artworks to them |
| `markers:read`      | Search and look up artworks and other places on the map              |
| `artists:read`      | Search and look up artists and their artworks                        |

`openid`, `profile` and `email` are for logging people in, see [Log in with Street Art Cities](/authentication/openid-connect/).

## Scopes don't add permissions

A scope only limits what your app can do. The person's own permissions still apply: with `edits:review`, your app can only review changes the person could review themselves on Street Art Cities. It's only meant for apps that help people review other people's changes; see [Reviewing through the API](/edits-api/review-queue/#reviewing-through-the-api).

If your app calls an endpoint without the right scope, you get a `403`:

```json
{ "error": "This app needs the edits:write scope to do that." }
```

## Which endpoints need which scope

| Scope               | Endpoints                                                                                                                                     |
| ------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| `edits:read`        | `GET /api/edits/mine`, `GET /api/edits/:id`, `POST /api/edits/views`                                                                          |
| `edits:write`       | `POST /api/edits`, `POST /api/edits/evaluate-permissions`                                                                                     |
| `edits:review`      | `POST /api/edits/:id/accept`, `/reject` and `/revert`                                                                                         |
| `collections:read`  | `GET` endpoints of the [Collections API](/collections-api/overview/), except `GET /api/collections/:id`, which anyone can use without a token |
| `collections:write` | `POST` and `DELETE` endpoints of the Collections API                                                                                          |
| `markers:read`      | All endpoints of the [Markers API](/markers-api/overview/)                                                                                    |
| `artists:read`      | All endpoints of the [Artists API](/artists-api/overview/)                                                                                    |
