Developer

Permission scopes

Scopes are the product's own feature codes. A credential can only narrow.

ScopeResourceVerbs
sales_customers/customersread · create · update · delete
purchases_vendors/vendorsread · create · update · delete
sales_invoices/invoicesread · create · update · delete
ops_products/itemsread · create · update · delete
sales_receipts/receiptsread · create
purchases_payments/paymentsread · create
finance_banking/bank-feedsread · create

A scope string is feature_code:verb, e.g. sales_invoices:create. In OAuth the user picks scopes on the consent screen; for API keys the Super Administrator picks them when minting. Either way the server checks three things on every call, and denies on the first failure:

  1. the credential is valid — exists, active, not expired, not revoked;
  2. the scope was granted at issuance;
  3. the user the credential is bound to still holds the right now.
⚠️Errors you will see

403 insufficient_scope — the credential was never granted this feature. 403 insufficient_permissions — the feature was granted but not this verb, or the bound user no longer holds it.

Two things that are not scopes

An API key can also carry a capability grant. It is not a feature and has no verbs — it decides where the key works, while the scopes above still decide what it may touch. Neither is available to an OAuth token.

GrantMinted withOpens
assistantAllow AI assistants (MCP)The MCP server at /mcp — see [Assistant tools](/developer/mcp-tools)
webhooksAllow webhook subscriptions/api/v1/webhooks/* — see [Subscribe an endpoint](/developer/subscribing)