List the scope catalog used by the Role Management UI

Returns every leaf scope (granular 1 row = 1 endpoint row in the
roles table) that the platform admin may include in a system role's
expanded scope set. Server-side filters: is_system=false,
s2s_only=false, reserved_reason IS NULL, deletedAt IS NULL.
Ordered by category, then scope_name.

Reserved scopes are excluded. A scope whose catalog row carries a
reserved_reason is declared but enforced by no handler, so composing it
into a role would grant an authority that unlocks nothing; the response
therefore omits the row entirely rather than flagging it, and the console
does not filter this set again.

Required scope: admin.platform.scopes.read. Required JWT tenantId:
ROOT_TENANT_ID (defense-in-depth).

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Responses

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json