generated: '2026-09-11' method: searched source: |- https://mcp.routebase.dev/.well-known/oauth-protected-resource and https://api.routebase.dev/.well-known/oauth-protected-resource (identical scopes_supported list), corroborated by https://docs.routebase.dev/api-keys/ which documents the same scope strings as API-key permissions. docs: https://docs.routebase.dev/api-keys/ model: |- Scopes are the granular API-key/OAuth permissions, grouped by functional area and formatted :. Keys default to full access or can be restricted to a subset of scopes and projects. OIDC identity scopes (openid, profile, email, ...) are served separately by the auth server metadata. authorization_server: https://auth.routebase.dev/ resource_scopes: - scope: projects:read - scope: projects:write - scope: projects:delete - scope: projects:manage-members - scope: specs:read - scope: specs:write - scope: specs:publish - scope: specs:delete - scope: specs:branch - scope: specs:merge - scope: specs:review - scope: tests:read - scope: tests:write - scope: tests:execute - scope: security:read - scope: security:write - scope: security:execute - scope: mock-server:read - scope: mock-server:manage - scope: monitoring:read - scope: monitoring:write - scope: gateway:read - scope: gateway:write - scope: gateway:deploy - scope: catalog:read - scope: catalog:write - scope: docs:read - scope: docs:write - scope: docs:publish - scope: docs:manage-portal - scope: notifications:read - scope: notifications:manage - scope: ai:use - scope: ai:manage - scope: billing:read - scope: billing:manage - scope: org:manage-members - scope: org:manage-teams - scope: org:manage-settings - scope: org:manage-security - scope: org:manage-governance - scope: org:delete oidc_scopes: source: https://auth.routebase.dev/.well-known/openid-configuration scopes_supported: [openid, profile, offline_access, name, given_name, family_name, nickname, email, email_verified, picture, created_at, identities, phone, address]