Skip to main content
Every request to Pomerado runs with a set of permissions. This page lists them and explains what limits a credential.

Permissions

Each page in the API reference names the permission its operation needs.

What limits a credential

A credential’s permissions are the smallest of three things:
  • Your role. A Business Member can’t manage the team. See roles and invitations.
  • The credential. An API key carries the permissions chosen when it was created, and an integration key at most four.
  • The account. A credential acts for one account: the one its key was created in, or the one you chose when signing in.
Changes take effect at once. If your role loses a permission, or you leave the account, every key and connected app loses it too, including for jobs still waiting to start.

Where a token works

  • An integration MCP reaches only its own integration’s tools, even with an account key or an account-wide sign-in.
  • An integration key and an integration MCP’s OAuth token work only on that MCP. Any other answers 403 forbidden, with error="insufficient_scope" in its WWW-Authenticate header.
  • A Pomerado MCP token works on the REST API too, with the same permissions and jobs.

When a permission is missing

The request answers 403 forbidden and nothing changes. Creating or rotating a key with a permission you don’t hold answers permission_not_held. See errors.