Scope reference
Every scope you can request, and exactly what user data each one returns.
Put scopes in the scope parameter of the authorization request, separated by spaces. The scopes you request are shown to the user on the consent screen as they are.
Scopes you can request
| Scope | Text on the consent screen | How it is granted |
|---|---|---|
profile.basic | UUID, nickname, email address | Default for all services |
profile.avatar | Profile picture URL | Default for all services |
service.domain.read | Domain details of the connected service | Manually granted by an administrator |
service.member_email.read | Member email address | Internal marker — you do not request it directly (see below) |
If you send no scope at all, or a value that is not in the list, the request is rejected with invalid_scope.
If you request a scope that has not been granted to your service, you get insufficient_scope.
★ Email policy — provided by default (opt-out)
Email is folded into profile.basic and provided by default.
It is not a scope you request separately; it comes along automatically once the user consents to profile.basic.
A service can turn email off (opt-out) so it does not receive it. In that case
the service.member_email.read marker is not attached to the effective scopes,
and the email field is left out of the /oauth/userinfo response.
In short, the email field is returned only when both of the following are true.
- The token's effective scopes include
profile.basic - Email sharing is not turned off for that service
Response fields that grow with scope
| Field | When it is returned | Description |
|---|---|---|
sub | Always | A per-service user identifier (pairwise) |
nickname | Always | The user's nickname |
scope | Always | The effective scopes of this token |
profile_image_url | profile.avatar | Profile picture URL. null if there is no picture |
email | Both conditions above are met | Email address |
service.domain.read
This scope reads the list of the user's own services that they have registered with 놀아 Account.
You do not need it for ordinary sign-in; use it only if you are building a service management tool.
It is granted manually by an administrator, and requesting it without a grant gives insufficient_scope.
To see how to read it, look at /oauth/domain-info in the API reference.
Recommended combinations
scope=profile.basic profile.avatar // typical social sign-in scope=profile.basic // when you don't need the picture
Requesting scopes you don't need makes the consent screen longer and increases drop-off. Request only what you actually use.