generated: '2026-09-19' method: searched source: openapi/relmcrm-com-openapi.yml (components.securitySchemes.oauth2) + well-known/relmcrm-com-oauth-authorization-server.json (RFC 8414, fetched live from https://api.relmcrm.com/.well-known/oauth-authorization-server) + well-known/relmcrm-com-oauth-protected-resource.json (RFC 9728) + https://relmcrm.com/docs (OAuth 2.1 section) docs: https://relmcrm.com/docs summary: >- One scope. Relm's OAuth 2.1 server issues a single coarse scope, crm, that grants read and write over the connected workspace; there is no read-only scope, no per-object scope and no admin/billing split. The scope set is the same in the OpenAPI, the RFC 8414 metadata (scopes_supported), the RFC 9728 protected-resource document (scopes_supported), the agent card, the MCP descriptor and every MCP tool's securitySchemes[] (oauth2, scopes [crm]). OAuth acts on live data only; test mode is API-key only. schemes: - name: oauth2 source: openapi/relmcrm-com-openapi.yml version: OAuth 2.1 (authorization code + PKCE S256 + refresh-token rotation) issuer: https://api.relmcrm.com flows: - flow: authorizationCode authorizationUrl: https://api.relmcrm.com/oauth/authorize tokenUrl: https://api.relmcrm.com/oauth/token refreshUrl: https://api.relmcrm.com/oauth/token registration_endpoint: https://api.relmcrm.com/oauth/register revocation_endpoint: https://api.relmcrm.com/oauth/revoke grant_types_supported: [authorization_code, refresh_token] response_types_supported: [code] code_challenge_methods_supported: [S256] token_endpoint_auth_methods_supported: [none, client_secret_post, client_secret_basic] dynamic_client_registration: RFC 7591 — clients register themselves; the dashboard lists connected apps and disconnecting one revokes all of its access immediately (changelog v0.17.0) discovery: authorization_server: well-known/relmcrm-com-oauth-authorization-server.json protected_resource: well-known/relmcrm-com-oauth-protected-resource.json resource: https://api.relmcrm.com/mcp live_only: true description: 'OAuth 2.1 with PKCE (S256) and dynamic client registration (RFC 7591). Live mode only; test mode is API-key only. Discovery: /.well-known/oauth-authorization-server.' scopes: - scope: crm description: Read and write the connected Relm workspace access: read-write over contacts, companies, deals, activities, pipelines, registry, automations, sequences, templates, connections, webhooks, usage and settings flows: - authorizationCode required_by: >- every MCP tool (securitySchemes oauth2 / scopes [crm] on all 41 tools in mcp/relmcrm-com-mcp-tools-list.json); the OpenAPI root security requirement; the agent card security[] sources: - openapi/relmcrm-com-openapi.yml - well-known/relmcrm-com-oauth-authorization-server.json - well-known/relmcrm-com-oauth-protected-resource.json granularity_note: >- Coarse by design for a workspace-scoped product; least-privilege for an agent is achieved by the MCP tool annotations (readOnlyHint / destructiveHint) that let a client gate confirmation, not by scope. An operator who needs a read-only credential has no scope to ask for.