> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pomerado.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Understand permissions and scope

> What each permission allows, and what limits the permissions a credential carries.

Every request to Pomerado runs with a set of permissions. This page lists them and explains what limits a credential.

## Permissions

| Permission | Allows |
| - | - |
| `tools:read` | Find tools and integrations, and read MCP setup |
| `tools:build` | Build tools, delete tools and change an integration's visibility |
| `runs:create` | Run tools and upload files for runs |
| `jobs:read` | Read jobs, answer their questions and manage webhooks |
| `jobs:cancel` | Cancel jobs |
| `logins:read` | List and read saved logins |
| `logins:manage` | Save, change, delete, import and share saved logins |
| `usage:read` | Read usage and quota |
| `api_keys:manage` | Manage API keys and connected apps with an API key |
| `billing:manage` | Manage a Personal account's plan with an API key |
| `team:manage` | Manage a Business account's members and invitations |

Each page in the [API reference](/api-reference/introduction) names the permission its operation needs.

## What limits a credential

A credential's permissions are the smallest of three things:

* **Your role.** A Business Member can't manage the team. See [roles and invitations](/guides/teams/roles-and-invitations).
* **The credential.** An API key carries the permissions chosen when it was created, and an integration key at most four.
* **The account.** A credential acts for one account: the one its key was created in, or the one you chose when signing in.

Changes take effect at once. If your role loses a permission, or you leave the account, every key and connected app loses it too, including for jobs still waiting to start.

## Where a token works

* An integration MCP reaches only its own integration's tools, even with an account key or an account-wide sign-in.
* An integration key and an integration MCP's OAuth token work only on that MCP. Any other answers `403 forbidden`, with `error="insufficient_scope"` in its `WWW-Authenticate` header.
* A Pomerado MCP token works on the REST API too, with the same permissions and jobs.

## When a permission is missing

The request answers `403 forbidden` and nothing changes. Creating or rotating a key with a permission you don't hold answers `permission_not_held`. See [errors](/errors).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.