Scopes
Ask for the least you need. The consent screen shows the member the description below, word for word, so a long list of scopes is a long list of reasons to decline.
Anything not on this list is refused with invalid_scope.
/.well-known/oauth-authorization-server and the others) advertise exactly those in
scopes_supported, and a scope appears there the day an endpoint starts serving it.Identity
| Scope | What the member is told | Available |
|---|---|---|
openid | Confirm who you are | Yes |
profile | See your name and profile picture | Yes |
email | See your email address | Yes |
The member's own data
| Scope | What the member is told | Available |
|---|---|---|
me.read | See your basic profile | Yes |
me.reservations.read | See your court bookings | Yes |
me.reservations.write | Book and cancel courts for you | Yes |
me.purchases.write | Buy court time for you, with a card you give the application | Yes, agent checkout |
me.results.read | See your match results | Yes |
me.memberships.read | See which clubs you belong to | Yes |
A club's data
| Scope | What the member is told | Available |
|---|---|---|
club.read | See the club's public details | Yes |
club.members.read | See the club's members | Yes |
club.members.write | Add and update the club's members | Yes |
club.courts.read | See the club's courts | Yes |
club.reservations.read | See the club's bookings | Yes |
club.reservations.write | Make and cancel the club's bookings | Yes |
club.checkout.write | Sell the club's court time to guests the application brings | Yes, agent checkout |
club.events.read | See the club's events | Not yet |
club.shop.orders.read | See the club's shop orders | Not yet |
Partner
Client credentials only — these describe an application acting with no member present.
| Scope | Meaning | Available |
|---|---|---|
partner.members.provision | Create members on behalf of a partner | Not yet |
partner.login.handoff | Sign a member in from a partner app | Yes |
Who may ask for what
| Client | May request |
|---|---|
| Registered by a club administrator, or by us | openid, profile, email, me.*, club.* |
| Self-registered (dynamic) | openid, profile, email, me.* — never a club's data |
| Client credentials | partner.*, club.* — me.* means nothing without a member |
club.* needs the club's permission too
Holding a club.* scope is not the same as being allowed to use it.
Before a club.* scope does anything, three separate parties must have agreed:
- Sporty approved your application;
- the club's administrator granted your application that club, and that scope;
- the member (where there is one) authorised your application for that club.
Any of the three can withdraw on their own, at any time, and your access ends at that moment.
If a club has not granted you, calls answer 403 access_denied with a message saying an
administrator must approve you first — not an error to retry, but one to go and ask about.
Which club a token acts for
You never tell us in the request body; we work it out from your client.
- A client belonging to one club always acts for that club.
- A client granted several clubs must name one with the
X-Clubheader. Without it you get400 club_required. The header chooses among clubs you have already been granted — it cannot give you one.
GET /api/partner/v1/clubs/me tells you which club a token ended up acting for.