Meet the new Scripe, live on October 7.Register

API v1 · OAuth

invalid_scope

HTTPWhen
400One or more requested scopes is invalid or unknown.

The requested scope string contains a token outside the closed scope list, or a refresh tried to widen scope beyond the consent. Scope strings are space-separated, case-sensitive <resource>:<verb> tokens.

Narrowing on refresh is allowed; widening requires a fresh trip through /authorize.