Scopes
What each scope of an API key unlocks, and how read and write scopes relate.
Version v1.1, updated
A scope is one thing an API key may do, such as reading products. The company administrator chooses the scopes when creating the key, and each operation needs at most one of them.
The scopes
GET /v1/me needs no scope, and GET /v1/openapi.json needs no key at all.
Read and write are separate
A write scope does not include the read scope of the same resource, nor the reverse. A system that creates orders and reads them back needs both orders:write and orders:read.
The external ids of a record use the write scope of its resource; warehouses use stock:write. An order that creates its customer on the fly also needs customers:write.
A missing scope
A call without the scope of its operation answers 403 insufficient_scope, with required_scopes. Scopes cannot be added to a key: create a new key with the scopes you need, then revoke the old one.
Related
- first-key
- keep-your-key-safe
- insufficient-scope