Available scopes
Choosing the right combination
A reporting integration with only the read scopes physically cannot
create or modify records — useful when sharing a key with a third party
or a BI tool.
Backing permissions
Scopes are not free-standing — each maps to a granular internal permission in the role model. When an admin issues a key, the chosen scopes are checked against the admin’s own permissions:
This prevents an admin with
org.api-keys but limited customer access
from minting a key that bypasses their own gates.

