Open source · API & Integration

OAuth Scope Matrix

Map OAuth scopes to operations and identify permissions broader than needed.

v0.1.0 · Node.js 22+ · MIT

Browse the public repository · View releases

Compare exported OAuth scope definitions, client grants and operation requirements. Reports the least-required set for each operation, the operations no grant covers, and the grants nothing requires.

This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.

Run the checked-in example

npm run example            # examples/clean, exits 0
node bin/oauth-scope-matrix.mjs --root examples/broken; echo $?   # 1
node bin/oauth-scope-matrix.mjs --root examples/incomplete; echo $?   # 2

Read the result

The rule catalog, the limits and the supported input dialect are in docs/scope-matrix-rules.md.

Where this check stops

What a pass means. The three documents are consistent with one another: every operation is covered by at least one client, and every scope named is one the catalog declares. That is the whole claim.

Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.

Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.