{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-products/nowinfinity/resources/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition"]},"type":"markdown"},"seo":{"title":"Authorisation Scopes","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"authorisation-scopes","__idx":0},"children":["Authorisation Scopes"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"overview","__idx":1},"children":["Overview"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In this article, we will look at the Connect scope values of Class APIs."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The Class API supports a subset of the OpenID Connect scope values, which are defined below."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["There is a set of custom values restricting the scope of the request to a Fund or Business, and this involves specifying the resources and operations available within that Fund or Business."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"supported-openid-connect-values","__idx":2},"children":["Supported OpenID Connect Values"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The Class API supports the following standard OpenID Connect scopes as defined in ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://openid.net/specs/openid-connect-core-1_0.html"},"children":["OpenID Connect Core 1.0"]},"."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Scope value"},"children":["Scope value"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["openid"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Required for all OpenID Connect requests. When specified, an ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://support.class.com.au/hc/en-au"},"children":["ID Token"]}," will be returned:",{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]}," - In the authorisation response, when ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["response_type"]}," contains ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["id_token"]},{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]}," - In the token response, when the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["response_type"]}," contains ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["code"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["profile"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["When specified, the following ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://openid.net/specs/openid-connect-core-1_0.html#StandardClaims"},"children":["Standard Claims"]}," will be included in UserInfo responses:",{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]}," - ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["name"]},{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]}," - ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["given_name"]},{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]}," - ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["middle_name"]},{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]}," - ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["family_name"]},{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]}," - ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["gender"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["email"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["When specified, the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["email"]}," ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://openid.net/specs/openid-connect-core-1_0.html#StandardClaims"},"children":["Standard Claims"]}," will be included in ID Tokens and UserInfo responses."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["address"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["When specified, the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["address"]}," ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://openid.net/specs/openid-connect-core-1_0.html#StandardClaims"},"children":["Standard Claims"]}," will be included in UserInfo responses."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["phone"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["When specified, the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["phone_number"]}," ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://openid.net/specs/openid-connect-core-1_0.html#StandardClaims"},"children":["Standard Claims"]}," will be included in UserInfo responses."]}]}]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"the-class_profile-scope-value","__idx":3},"children":["The class_profile Scope Value"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When combined with the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["openid"]}," scope value, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["class_profile"]}," allows the following additional OpenID Claims to be retrieved from the UserInfo Endpoint:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field Name"},"children":["Field Name"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["business_name"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The name of the user's business"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["business_code"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The code for the user's business in Class"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["business_address"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The address of the user's business, in the same format as the standard address Claim"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["business_phone_number"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The phone number of the user's business, in the same format as the standard phone_number Claim"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["class_role"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["A comma-delimited list of strings describing the user's role in Class, e.g. Administrator, Access Controller, adviser"]}]}]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"the-target-scope-value","__idx":4},"children":["The target Scope Value"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This scope value specifies if the client is requesting Business or Fund level access. This enables the client to specify a specific Business or Fund or allow the authorising user to select one."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This scope value is ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["required"]}," if any access specifiers are present."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The format of this scope value is ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["target:context"]},". The parameters of the URL are specified as follows:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["b:"]}," Indicates the client is requesting access to a Business. The user will be prompted to select a Business."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["f:"]}," Indicates the client is requesting access to a single Fund. The user will be prompted to select a Fund."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["b/BUSINESS:"]}," Indicates the client is requesting access to the specific Business with the code BUSINESS."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["f/BUSINESS/FUND:"]}," Indicates the client is requesting access to the specific Fund in Business BUSINESS with code FUND"]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Please note that the above request to access a single fund and request to access a specific fund in a business code is currently not supported."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"access-specifier-scope-values","__idx":5},"children":["Access Specifier Scope Values"]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Refer to the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/class/apis"},"children":["documentation"]}," for the specific API endpoints you wish to use to determine the access specifiers required by your integration."]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Class ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["strongly recommends"]}," that your integration requests the minimum set of scopes possible and does not request unnecessary scopes."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["These scope values allow the client to request access to specific resources, and the operations they wish to perform using those resources."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The format of this scope value is context, resource and operation. The components are defined as follows:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["context"]},": The context for the resource that access is being requested for, e.g. business, fund. This component is ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["required"]}," for each access specifier."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["resource"]},": Indicates the resources that access is being requested for, e.g. members, funds, details. If omitted, the request is for ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["all"]}," resources within the specified context."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["operation"]},": Indicates the operation the client is requesting access to perform. e.g. read, maintain, create. If omitted, it defaults to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["read"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"supported-access-specifiers","__idx":6},"children":["Supported Access Specifiers"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Specifier"},"children":["Specifier"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Implied Permissions"},"children":["Implied Permissions"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["business.fund.list"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["List summarised data of funds in the business"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["-"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["business.fund.create"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Create new funds in the business"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["-"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["business.details.read"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["View details about users of the business"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["-"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["fund.details.read"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["View basic fund details"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["-"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["fund.details.maintain"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["View and maintain basic fund details"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["fund.details.read"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["fund.member.read"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["View member details"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["-"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["fund.member.maintain"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["View and maintain member details"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["fund.member.read"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["fund.read"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["View all fund information"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["fund.*.read"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["fund.maintain"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["View and maintain all fund information"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["fund.*.maintain"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"considerations-when-requesting-offline_access","__idx":7},"children":["Considerations When Requesting offline_access"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following additional requirements apply when the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["offline_access"]}," scope is requested:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["offline_access"]}," is only supported for the authorisation grant flow used by ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/class/resources/authorisation-code-flow"},"children":["Authorisation Code Flow"]},". It cannot be used by Implicit Flow."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["When making an Authorisation request, the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["prompt"]}," parameter ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["must"]}," be included and its value ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["must"]}," be ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["consent"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["include_granted_scopes"]}," scope value cannot be used concurrently with the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["offline_access"]}," scope value. Requests for offline access must always include the full set of required access specifiers."]}]}]},"headings":[{"value":"Authorisation Scopes","id":"authorisation-scopes","depth":1},{"value":"Overview","id":"overview","depth":2},{"value":"Supported OpenID Connect Values","id":"supported-openid-connect-values","depth":2},{"value":"The class_profile Scope Value","id":"the-class_profile-scope-value","depth":2},{"value":"The target Scope Value","id":"the-target-scope-value","depth":2},{"value":"Access Specifier Scope Values","id":"access-specifier-scope-values","depth":2},{"value":"Supported Access Specifiers","id":"supported-access-specifiers","depth":3},{"value":"Considerations When Requesting offline_access","id":"considerations-when-requesting-offline_access","depth":2}],"frontmatter":{"seo":{"title":"Authorisation Scopes"}},"lastModified":"2025-11-13T12:04:05.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/nowinfinity/resources/authorisation-scopes","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}