How do you set up API access in Marketing Cloud using Installed Packages? What OAuth scopes are commonly required?
Suggested answer
API access is managed via Installed Packages in Marketing Cloud Setup (Platform > Apps > Installed Packages).
Component types:
— Server-to-Server: OAuth 2.0 client credentials flow. Used for back-end integrations. Provides client_id and client_secret.
— Public App: OAuth 2.0 with PKCE. For front-end or mobile apps that cannot store secrets.
— Web App: OAuth 2.0 authorisation code flow. For web apps with server-side components.
Common OAuth scopes:
— email:read/write/send — Email Studio access
— data:read/write — Data Extension access
— list:read/write — Subscriber list management
— contacts:read/write — Contact Builder
— journeys:read/write — Journey Builder
— assets:read/write/publish — Content Builder
IP allowlisting: Restrict API access to specific IP addresses or CIDR ranges in the Installed Package settings for additional security.
Token management: Access tokens expire in 1,080 seconds (18 minutes). Cache and reuse — do not request a new token per API call.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.