Currently it checks the uid in the special list: https://github.com/zalando-stups/kio/blob/master/src/org/zalando/stups/kio/api.clj#L42 This should be allowed to any user that has the correct scope. please, @prayerslayer :)