ADO.NET Provider for Talkdesk

Build 26.0.9770

OAuth Scopes and Endpoints

Required Scopes and Endpoint Domains for Talkdesk

When integrating with Talkdesk, your application needs specific permissions to interact with the API.

These permissions are defined by access scopes, which determine what data your application can access and what actions it can perform.

This topic provides information about the required access scopes and endpoint domains for the Talkdesk provider.

Understanding Scopes

Scopes are a way to limit an application's access to a user's data. They define the specific actions that an application can perform on behalf of the user.

For example, a read-only scope might allow an application to view data, while a full access scope might allow it to modify data.

Required Scopes for Talkdesk

The provider accesses Talkdesk data on a read-only basis, so the custom OAuth application you register must be granted read access to the resources you intend to query. You select these scopes when you create the application (see Creating a Custom OAuth Application).

Add the scopes that correspond to the data you want to access. If the application is missing a scope that a queried table requires, the Talkdesk token request or the query fails.

The following table lists the minimal scope required by each view and stored procedure. The scope names match the values shown in the Talkdesk OAuth Clients screen when you add scopes to the application.

EntityStatement TypesMinimal Required Scopes
UsersSELECTusers:read
TeamsSELECTindustries-scheduler-teams:read
QueuesSELECTqueues:read
UserQueuesSELECTqueues-users:read
ContactsSELECTcontacts:read
ContactIntegrationsSELECTcontacts-integrations:read
CasesSELECTcases-public:read
CaseFieldsSELECTcase-fields-public:read
CallbacksSELECTschedule-callbacks:read
CampaignsSELECTcampaigns:read
CampaignUsersSELECTcampaigns:read
CampaignRecordListsSELECTcampaigns:read
CampaignDoNotCallListsSELECTcampaigns:read
RecordListsSELECTrecord-lists:manage
RecordListRecordsSELECTrecord-lists:manage
DoNotCallListsSELECTdo-not-call-lists:manage
DoNotCallEntriesSELECTdo-not-call-lists:manage
AttributesSELECTattributes:read
AttributeCategoriesSELECTattributes:read
AttributeUsersSELECTattributes:read
PromptsSELECTprompts:read
PromptFlowsSELECTprompts:read
PromptsUsageSELECTprompts:read
AccountSELECTaccount:read
BillingAccountsSELECTexpress-accounts:read
InvoicesSELECTexpress-accounts-invoices:read
ProductsSELECTexpress-products:read
SubscriptionsSELECTexpress-accounts-subscriptions:read
WalletsSELECTaccount-wallets:read
MonthlyUsageSELECTexpress-accounts-usage:read
BucketConfigurationsSELECTbucket-configurations:read
GuardianUsersSELECTguardian-users:read
GuardianUserRolesSELECTguardian-users:read
GuardianSessionLogsSELECTguardian-sessions:read
GuardianCasesSELECTguardian-cases:read
GuardianCallsQualitySELECTguardian-call-quality:read
ScimUsersSELECTscim
ResourceTypesSELECTscim
GetCallRecordingsEXECUTErecordings:read
DownloadPromptAudioFileEXECUTEprompts:download

Report views: Every view whose name ends in Report (for example, CallsReport) requires both data-reports:read and data-reports:write. The provider needs write access because each report query first creates a temporary report job and then reads its results.

For the authoritative, most up-to-date scope required by each endpoint, refer to the Talkdesk API documentation.

Understanding Endpoint Domains

Endpoint domains are the specific URLs that the application needs to communicate with in order to authenticate, retrieve records, and perform other essential operations.

Allowlisting these domains ensures that the network traffic between your application and the API is not blocked by firewalls or security settings.

Note: Most users do not need to make any special configurations. Allowlisting is typically only necessary for environments with strict security measures, such as restricted outbound network traffic.

Required Endpoint Domains for Talkdesk

DomainAlways RequiredDescription
talkdeskid.comTrueThe Talkdesk identity domain the provider uses to obtain and refresh OAuth access tokens. The exact domain depends on your Region (see the region-specific table below).
talkdeskapp.comTrueThe Talkdesk API domain the provider uses to retrieve data. The exact domain depends on your Region (see the region-specific table below).

Region-Specific Domains

Some providers use different domain suffixes or URLs based on the region where their services are hosted.

This regional segmentation helps improve performance, assists with regional data regulations compliance, and ensures better service availability.

When setting up the connection properties for your application, it's important to specify the appropriate region. The following table lists the placeholders for different regions:

RegionAuthentication DomainAPI Domain
US (default)talkdeskid.comapi.talkdeskapp.com
EUtalkdeskid.euapi.talkdeskapp.eu
CAtalkdeskidca.comapi.talkdeskappca.com
AUtalkdeskid.auapi.mytalkdesk.au
UKtalkdeskid.co.ukapi.talkdeskapp.co.uk
FedRamptalkdeskid-pubsec.comapi.talkdeskapp-pubsec.com

Copyright (c) 2026 CData Software, Inc. - All rights reserved.
Build 26.0.9770