OAuth & Sign in with Sporty

Scopes

Every scope, what the member is told it means, and which kinds of client may ask for it.

Ask for the least you need. The consent screen shows the member the description below, word for word, so a long list of scopes is a long list of reasons to decline.

Anything not on this list is refused with invalid_scope.

Some scopes are named ahead of the API. A scope marked Not yet can be requested, and a member can approve it, but no endpoint answers to it yet, so a token holding it reaches nothing more. Build against the scopes marked Yes. The discovery documents (/.well-known/oauth-authorization-server and the others) advertise exactly those in scopes_supported, and a scope appears there the day an endpoint starts serving it.

Identity

ScopeWhat the member is toldAvailable
openidConfirm who you areYes
profileSee your name and profile pictureYes
emailSee your email addressYes

The member's own data

ScopeWhat the member is toldAvailable
me.readSee your basic profileYes
me.reservations.readSee your court bookingsYes
me.reservations.writeBook and cancel courts for youYes
me.purchases.writeBuy court time for you, with a card you give the applicationYes, agent checkout
me.results.readSee your match resultsYes
me.memberships.readSee which clubs you belong toYes

A club's data

ScopeWhat the member is toldAvailable
club.readSee the club's public detailsYes
club.members.readSee the club's membersYes
club.members.writeAdd and update the club's membersYes
club.courts.readSee the club's courtsYes
club.reservations.readSee the club's bookingsYes
club.reservations.writeMake and cancel the club's bookingsYes
club.checkout.writeSell the club's court time to guests the application bringsYes, agent checkout
club.events.readSee the club's eventsNot yet
club.shop.orders.readSee the club's shop ordersNot yet

Partner

Client credentials only — these describe an application acting with no member present.

ScopeMeaningAvailable
partner.members.provisionCreate members on behalf of a partnerNot yet
partner.login.handoffSign a member in from a partner appYes

Who may ask for what

ClientMay request
Registered by a club administrator, or by usopenid, profile, email, me.*, club.*
Self-registered (dynamic)openid, profile, email, me.* — never a club's data
Client credentialspartner.*, club.* — me.* means nothing without a member

club.* needs the club's permission too

Holding a club.* scope is not the same as being allowed to use it.

Before a club.* scope does anything, three separate parties must have agreed:

  1. Sporty approved your application;
  2. the club's administrator granted your application that club, and that scope;
  3. the member (where there is one) authorised your application for that club.

Any of the three can withdraw on their own, at any time, and your access ends at that moment. If a club has not granted you, calls answer 403 access_denied with a message saying an administrator must approve you first — not an error to retry, but one to go and ask about.

Which club a token acts for

You never tell us in the request body; we work it out from your client.

  • A client belonging to one club always acts for that club.
  • A client granted several clubs must name one with the X-Club header. Without it you get 400 club_required. The header chooses among clubs you have already been granted — it cannot give you one.

GET /api/partner/v1/clubs/me tells you which club a token ended up acting for.