Scopes
xixo publishes its scopes beneath the xixo: namespace of the masks tenant it
signs in with. A token carries the ones its holder was granted; anything outside the namespace
is ignored. xixo:settings:admin is never asked for at sign-in.
Generated from the code by ./dev reference. CI fails when this page and the code disagree.
| Scope | Means | Asked at sign-in | MCP tools | GraphQL |
|---|---|---|---|---|
xixo:catalog:read |
Read your catalog | yes | search feed |
13 root fields |
xixo:catalog:write |
Change your catalog | yes | connect |
20 root fields |
xixo:web:read |
Search the web | yes | — | — |
xixo:web:keep |
Keep pages from the web | yes | — | — |
xixo:mcp:call |
Use the servers you have added | yes | proxied tools | — |
xixo:resources:read |
Read your places | yes | resource |
2 root fields |
xixo:resources:command |
Act on your places | yes | resource writes |
8 root fields |
xixo:settings:read |
Read your settings | yes | — | 1 root field |
xixo:settings:write |
Change your settings | yes | — | 1 root field |
xixo:settings:admin |
Change everyone’s settings | no | — | — |