Permissions
Each page in the API reference names the permission its operation needs.
What limits a credential
A credential’s permissions are the smallest of three things:- Your role. A Business Member can’t manage the team. See roles and invitations.
- The credential. An API key carries the permissions chosen when it was created, and an integration key at most four.
- The account. A credential acts for one account: the one its key was created in, or the one you chose when signing in.
Where a token works
- An integration MCP reaches only its own integration’s tools, even with an account key or an account-wide sign-in.
- An integration key and an integration MCP’s OAuth token work only on that MCP. Any other answers
403 forbidden, witherror="insufficient_scope"in itsWWW-Authenticateheader. - A Pomerado MCP token works on the REST API too, with the same permissions and jobs.
When a permission is missing
The request answers403 forbidden and nothing changes. Creating or rotating a key with a permission you don’t hold answers permission_not_held. See errors.