generated: '2026-09-17' method: searched source: https://developer.seismic.com/seismicsoftware/docs/scopes-1 docs: https://developer.seismic.com/seismicsoftware/docs/scopes-1 description: Seismic OAuth 2.0 / OpenID Connect scopes. The 39 scopes with descriptions below are the ones Seismic documents on its public scopes reference. The authorization server at https://auth.seismic.com advertises 389 scopes in total in its anonymous OpenID Connect discovery document — the large remainder are internal service scopes (ums_*, matrix_*, disc_*, bff_* and similar) that the public reference does not describe, so they are counted but not enumerated here with invented descriptions. authorization_server: issuer: https://auth.seismic.com discovery: https://auth.seismic.com/.well-known/openid-configuration artifact: well-known/seismic-auth-openid-configuration.json probed: '2026-09-17' http_status: 200 authorization_endpoint: https://auth.seismic.com/connect/authorize token_endpoint: https://auth.seismic.com/connect/token introspection_endpoint: https://auth.seismic.com/connect/introspect revocation_endpoint: https://auth.seismic.com/connect/revocation jwks_uri: https://auth.seismic.com/.well-known/openid-configuration/jwks grant_types_supported: - authorization_code - client_credentials - refresh_token - implicit - password - urn:ietf:params:oauth:grant-type:device_code - impersonation - central - delegation - legacy_remember_me - urn:ietf:params:oauth:grant-type:token-exchange - token-exchange code_challenge_methods_supported: - plain - S256 token_endpoint_auth_methods_supported: - client_secret_basic - client_secret_post scopes_advertised_count: 389 counts: documented_with_description: 39 advertised_by_authorization_server: 389 recorded_here: 50 scopes: - name: seismic.self.view description: Read information about the current user documented: true advertised_by_authorization_server: true - name: seismic.self.manage description: Manage information about the current user documented: true advertised_by_authorization_server: true - name: seismic.user.view description: Read profile and group about all users in the system documented: true advertised_by_authorization_server: true - name: seismic.user.manage description: Manage profile and group information about any user in the system documented: true advertised_by_authorization_server: true - name: seismic.configuration.view description: Read information about how the system is configured documented: true advertised_by_authorization_server: true - name: seismic.configuration.manage description: Manage information about how the system is configured documented: true advertised_by_authorization_server: true - name: seismic.reporting description: Access to tenants reporting data documented: true advertised_by_authorization_server: true - name: seismic.delivery description: Access to all delivery methods including email, generated livesend links, and custom delivery options documented: true advertised_by_authorization_server: true - name: seismic.library.view description: Read item information and properties about an object (content manager, doccenter, newscenter) documented: true advertised_by_authorization_server: true - name: seismic.library.manage description: Manage content, and folders, within a tenant (e.g. add, update, and delete) documented: true advertised_by_authorization_server: true - name: seismic.workspace.view description: Read item information and properties about an object, with download capabilities documented: true advertised_by_authorization_server: true - name: seismic.workspace.manage description: Manage content, and folders, within a users workspace (e.g. add, update, and delete) documented: true advertised_by_authorization_server: true - name: seismic.search description: Access to search for content in all repositories documented: true advertised_by_authorization_server: true - name: seismic.gen-search description: Access to generative search functionality documented: true advertised_by_authorization_server: true - name: seismic.livedoc_express.view description: Read LiveDoc Express batch and variant information documented: true advertised_by_authorization_server: true - name: seismic.livedoc_express.manage description: Manage LiveDoc Express batch and variant data and execute batch generations documented: true advertised_by_authorization_server: true - name: seismic.planner.view description: Read item information and properties about objects in planner documented: true advertised_by_authorization_server: true - name: seismic.planner.manage description: Manage projects, tasks, and their item information and properties documented: true advertised_by_authorization_server: true - name: seismic.custom_property.view description: Read information about custom properties documented: true advertised_by_authorization_server: true - name: seismic.custom_property.manage description: Manage custom properties in the system documented: true advertised_by_authorization_server: true - name: seismic.custom_schema.view description: Read information about the custom schemas present in the system documented: true advertised_by_authorization_server: true - name: seismic.custom_schema.manage description: Manage custom schemas in the system documented: true advertised_by_authorization_server: true - name: seismic.workflow.view description: Read running approval workflow information and workflow properties documented: true advertised_by_authorization_server: true - name: seismic.workflow.manage description: Take actions on approval workflows like approve, reject or submit documented: true advertised_by_authorization_server: true - name: seismic.engagement.view description: Read information about engagements such as Seismic emails, links, and meetings documented: true advertised_by_authorization_server: true - name: seismic.engagement.manage description: Manage information about engagements such as Seismic emails, links, and meetings documented: true advertised_by_authorization_server: true - name: seismic.learning.view description: Read information about objects associated with Learning documented: true advertised_by_authorization_server: true - name: seismic.learning.manage description: Read and modify information about objects associated with Learning documented: true advertised_by_authorization_server: true - name: seismic.global_variable.view description: View global variables in the system documented: true advertised_by_authorization_server: true - name: seismic.global_variable.manage description: Manage global variables in the system documented: true advertised_by_authorization_server: true - name: seismic.channel.view description: Read information about channels documented: true advertised_by_authorization_server: true - name: seismic.channel.manage description: Manage channels in the system documented: true advertised_by_authorization_server: true - name: seismic.lessons.view description: Read information about Lessons in Learning documented: true advertised_by_authorization_server: true - name: seismic.lessons.manage description: Manage information about Lessons in Learning documented: true advertised_by_authorization_server: true - name: seismic.skills.view description: Read information about objects associated with skills documented: true advertised_by_authorization_server: true - name: seismic.skills.manage description: Read and modify information about objects associated with skills documented: true advertised_by_authorization_server: true - name: seismic.social.view description: Grants permission to view and read social features and related data within the system documented: true advertised_by_authorization_server: true - name: seismic.social.manage description: Grants permission to create, update, and manage social features and related data documented: true advertised_by_authorization_server: true - name: seismic.distribution_list.manage description: Create, read, update and delete email distribution lists owned by the authenticated user documented: true advertised_by_authorization_server: true - name: seismic.mcp description: Required to call the remote MCP server. Named in the RFC 9728 protected-resource metadata for https://mcp.seismic.com/v1 and in the MCP server documentation; it does not by itself grant tool invocation, which needs tenant-administrator permissions. documented: false advertised_by_authorization_server: true - name: seismic.webhook description: Advertised by the authorization server. Backs the webhook/event subscription surface documented at /docs/webhooksoverview. documented: false advertised_by_authorization_server: true - name: seismic.events description: Advertised by the authorization server alongside seismic.webhook for the event surface. documented: false advertised_by_authorization_server: true - name: seismic.audit.view description: Advertised by the authorization server. Backs the audit query endpoints in the API reference. documented: false advertised_by_authorization_server: true - name: seismic.crm description: Advertised by the authorization server. Backs the CRM context tools exposed by the MCP server. documented: false advertised_by_authorization_server: true - name: seismic.email description: Advertised by the authorization server. Backs the email delivery surface. documented: false advertised_by_authorization_server: true - name: seismic.intelligence description: Advertised by the authorization server. documented: false advertised_by_authorization_server: true - name: offline_access description: Standard OAuth 2.0 scope for refresh tokens; advertised by the authorization server. documented: false advertised_by_authorization_server: true - name: openid description: OpenID Connect. Advertised by the authorization server. documented: false advertised_by_authorization_server: true - name: email description: OpenID Connect standard claim scope. documented: false advertised_by_authorization_server: true - name: profile description: OpenID Connect standard claim scope. documented: false advertised_by_authorization_server: true notes: - The MCP resource https://mcp.seismic.com/ advertises scopes_supported [seismic.engagement.manage, seismic.gen-search]; https://mcp.seismic.com/v1 advertises [seismic.mcp]. - 'Scope names follow two conventions: the public seismic.. family, and an older flat internal family (library, reporting, download, webhook). Only the first is documented.' - The local OpenAPI documents declare a bearer HTTP scheme rather than an oauth2 securityScheme, so derive-oauth-scopes.py finds no scopes in the spec; every scope here comes from the provider docs and the live discovery document, not from the spec.