What are scopes?
Scopes control what your app can do when users connect it to their Fanvue account using OAuth 2.0. Each scope grants a specific access level that determines which resources your app can read from or write to. When you create your OAuth app, you’ll specify which scopes you need based on what your app does. Your app then has access only to the data and features it needs, following the principle of least privilege. To learn more about OAuth 2.0 and how to set up your app, see the OAuth Tutorial.How scopes work
- Permission control: Each scope grants access to specific resources and actions
- Request validation: Every API request checks if your access token has the required scopes
- Error handling: Requests without sufficient scopes return a
403 Forbiddenerror - App configuration: Scopes are set when you create your OAuth app and determine which scopes users can grant
Available scopes
The following table lists all available scopes organised by resource:Scope descriptions
read:selfAccess your own user profile information, including basic account details and settings.
read:chatRead chat conversations, messages, and chat-related data. This includes viewing chat lists and message history.
write:chatCreate new chats and send messages. This scope is required for any chat-related actions that modify data.
read:fanAccess fan-related data and information within the platform.
read:creatorAccess creator profiles, content, and creator-specific information.
write:creatorModify creator profiles, settings, and creator-specific data.
read:experienceExchange a fan’s experience token for the resolved experience and the fan’s identity, so an embedded fan-facing experience can render the right content. Also required to receive the
creator.experience_subscription.* webhooks.
write:experienceRequest that the creator publish or unpublish a fan-facing experience. The app mints a request token; the creator confirms and Fanvue performs the change.
read:mediaAccess media files, images, videos, and other content assets.
write:mediaUpload, modify, and manage media files and content assets. Also required for vault folder management.
read:postRead posts, including post details, comments, likes, and tips.
write:postCreate, edit, and manage posts and content on behalf of users.
read:insightsAccess analytics, metrics, and insights data for performance tracking.
read:tracking_linksRead tracking links and the users associated with them, including per-user tracking metadata.
write:tracking_linksCreate and delete tracking links.
read:agencyRead agency information, including the agency’s team members.
write:agencyManage agency team members and invites, including inviting new team members and creators.
Setting up scopes
When creating your OAuth app, you’ll configure which scopes your app can request:- Choose the scopes your app actually needs
- Follow the principle of least privilege: only request what’s necessary
- Consider your users: they’ll see what permissions you’re asking for
Error handling
If your access token doesn’t have the required scopes for a request, you’ll receive:403 Forbidden HTTP status code. Make sure your app requests all necessary scopes and that users have granted them.