Developer reference
Choose API scopes
Map an integration’s intended operations to the smallest registered permission set.
Scopes are checked against the registered method and route. A scope grants a class of registered operations, not arbitrary database access.
Scope reference
| Scope | Capability |
|---|---|
read:finance | Read registered financial resources. |
write:finance | Create or update registered financial resources. |
delete:finance | Use registered deletion operations, subject to domain constraints. |
export:finance | Reserved export permission; no complete-history export endpoint is implied. |
manage:tokens | List, create and revoke API tokens. |
imports:read | Read import setup, jobs, sources, rows and previews. |
imports:write | Configure and explicitly run import lifecycle actions. |
Choose by task
For an account reader, begin with read:finance. For an import progress monitor, use imports:read. Starting or undoing an import needs explicit imports:write intent; reading a preview does not waive that boundary.
Use the endpoint catalog to confirm each method and scope. Unknown operations fail closed. A token with deletion permission can still receive a domain refusal when a record is linked or unsafe to remove.
Change permissions deliberately
Add a scope only when a concrete feature requires it. Test the expected allowed request and a denied request using an appropriately restricted credential. Do not respond to 403 by granting every scope without understanding which operation failed.
Read authentication for the identity requirements and errors for safe refusal handling.