VitrinaAPI
Authentication and API keys

Scopes

Every scope a credential can carry: what each one opens, which roles carry it, and which are sensitive or owner-only.

This page is generated from src/services/scope-catalog.ts — the catalogue the backend checks on every call — and from the route table that spends those permissions. It cannot name a scope that does not exist, and the "What it opens" column is recounted on every build: it is the number of operations that require the scope today, not a figure somebody typed.

The chapter that explains how a credential is minted, read and revoked is Authentication and API keys.

What a scope is

A permission shaped resource:action. What sits before the colon is the resource; what sits after it is what you may do with it. A credential carries its own in a list and holds nothing beyond them.

  • An operation may accept several scopes, and one is enough. The middleware guarding it takes several and reads them as an OR: carry any one of them and you are through. That is why the same operation is counted in more than one row.
  • Nobody hands out what they do not hold. When a credential is minted, the platform rejects any scope the minter does not carry. An API key never comes out wider than the person or credential that created it.
  • * exists and it is not for you. It is the wildcard on the platform bootstrap credentials. No role carries it, and the mint form will not take it.
  • A scope is not the whole gate. It says which family of operations you may call, not which records you may see: record visibility — and, where it applies, published-inventory visibility — still sits on top. A scope opens the route; it does not decide what comes back.
  • A scope with no route is not a dead scope. A few of them guard a field inside another response, a tool on the MCP server or a background job, and one or two are reserved for an operation that does not exist yet. The table says so rather than hiding them.

How to read a row

  • Scope — the exact string that goes in scopes when the credential is minted. The table is sorted by that string, so the scopes of one resource sit together.
  • What it opens — how many API operations require it today, followed by the areas of the contract they reach. When the area is one of the chapters this site publishes, it is linked; otherwise the tag is named as the contract spells it. The tier of those operations closes the cell: estable changes only through deprecation, beta may change with a changelog entry, interna is not part of the public API and may change without notice.
  • Roles — which of the four built-in roles carry it. A custom role is built from any admin scope, never from an owner one.
  • Marks — owner only when no admin carries it; sensitive when one of its operations touches personal or health data beyond ordinary contact fields; connector preset when the guided connect flow for a Connected app includes it; pk_ when a browser-side publishable key carries it.

Every scope

182 scopes: the ones the built-in roles hand out, plus the connector preset and the publishable-key set. Deprecated spellings are at the foot of the page.

ScopeWhat it opensRolesMarks
ads:read20 operations · Ads · tier: betaOwner · Admin—
ads:write10 operations · Ads · tier: betaOwner · Admin—
ai_agents:read47 operations · AI agents, Onboarding, Templates · tier: beta and internaOwner · Admin—
ai_agents:simulate25 operations · AI agents, Conversation Coach, Mejoras, +1 more · tier: internaOwner · Admin—
ai_agents:write71 operations · AI agents, Onboarding, Conversation Coach, +1 more · tier: beta and internaOwner · Admin—
analytics:read37 operations · Analytics, Dealer Alerts, Insights · tier: beta and internaOwner · Admin · Supervisor · Agentconnector preset
analytics:write5 operations · Analytics · tier: internaOwner · Admin—
api_keys:read2 operations · API keys, OAuth · tier: beta and internaOwner · Admin—
api_keys:write6 operations · API keys, PublishableKeys, OAuth · tier: beta and internaOwner · Admin—
appointment_types:read3 operations · Appointments, Deposit Policies · tier: beta and internaOwner · Admin · Supervisor · Agentconnector preset
appointment_types:write6 operations · Appointments, Deposit Policies · tier: beta and internaOwner · Admin—
appointments:delete1 operation · Appointments · tier: betaOwner · Admin · Supervisor · Agent—
appointments:intake4 operations · Widget · tier: internaOwner · Adminpk_
appointments:read8 operations · Appointments, Calendar overlays · tier: beta and internaOwner · Admin · Supervisor · Agentconnector preset
appointments:write5 operations · Calendar overlays, Appointments · tier: beta and internaOwner · Admin · Supervisor · Agent—
audit:read1 operation · Audit · tier: internaOwner · Admin—
bank_movements:read3 operations · Bank Movements · tier: internaOwner · Admin—
bank_movements:write3 operations · Bank Movements · tier: internaOwner · Admin—
billing:read10 operations · Payment method · tier: beta and internaOwner · Admin—
billing:write8 operations · Payment method · tier: beta and internaOwnerowner only
campaigns:read17 operations · Audiences, Campaigns, WhatsApp Flows, +3 more · tier: beta and internaOwner · Admin · Supervisor · Agent—
campaigns:write38 operations · WhatsApp templates, Campaigns, WhatsApp Flows, +3 more · tier: beta and internaOwner · Admin—
clinic:read73 operations · Clinic, Patient register, Clinic pricing, +7 more · tier: beta and internaOwner · Admin · Supervisor · Agentsensitive · connector preset
clinic:write56 operations · Clinic, Patient register, Clinic services, +3 more · tier: beta and internaOwner · Adminsensitive
clinic_admin:write53 operations · Clinic, Templates and retention, Clinic pricing, +4 more · tier: beta and internaOwner · Adminsensitive
clinic_insights:read12 operations · Clinic, Clinic caja · tier: internaOwner · Admin—
clinic_money:read48 operations · Clinic caja, Clinic budgets, Clinic, +3 more · tier: beta and internaOwner · Admin—
clinic_money:write66 operations · Clinic caja, Clinic budgets, Clinic bank feed, +3 more · tier: beta and internaOwner · Admin—
clinic_patients:read8 operations · Patient register · tier: betaOwner · Adminsensitive
clinic_patients:write10 operations · Patient register · tier: beta and internaOwner · Adminsensitive
clinic_record:read27 operations · Clinical record, Consents, Record documents · tier: betaOwner · Adminsensitive
clinic_record:write30 operations · Clinical record, Consents, Record documents · tier: betaOwner · Adminsensitive
companies:read2 operations · Companies · tier: betaOwner · Admin · Supervisor · Agent—
companies:write3 operations · Companies · tier: betaOwner · Admin · Supervisor · Agent—
consignments:read14 operations · Consignments · tier: beta and internaOwner · Admin—
consignments:write9 operations · Consignments, Vehicles · tier: beta and internaOwner · Admin—
contacts:read18 operations · Contacts, Contact Completeness · tier: beta and internaOwner · Admin · Supervisor · Agentconnector preset
contacts:write21 operations · Contacts · tier: betaOwner · Admin · Supervisor · Agent—
conversations:read28 operations · Conversations, Copilot, Custom attributes, +3 more · tier: beta and internaOwner · Admin · Supervisor · Agentconnector preset
conversations:write36 operations · Conversations, Mejoras · tier: beta and internaOwner · Admin · Supervisor · Agent—
copilot:read9 operations · Copilot · tier: internaOwner · Admin · Supervisor · Agent—
copilot:write15 operations · Copilot · tier: internaOwner · Admin · Supervisor · Agent—
corrections:read19 operations · Conversation Coach, Mejoras, AI agents · tier: beta and internaOwner · Admin · Supervisor · Agent—
corrections:write10 operations · Conversation Coach, Mejoras · tier: internaOwner · Admin · Supervisor · Agent—
credit_applications:read5 operations · Credit applications, Financial Institutions · tier: beta and internaOwner · Admin—
credit_applications:write5 operations · Credit applications · tier: betaOwner · Admin—
custom_attributes:read3 operations · Custom attributes · tier: betaOwner · Admin · Supervisor · Agent—
custom_attributes:write4 operations · Custom attributes · tier: betaOwner · Admin—
dealer_sites:read1 operation · Dealer sites · tier: internaOwner · Admin—
dealer_sites:write1 operation · Dealer sites · tier: internaOwner · Admin—
dealership_economics:read25 operations · Insights, Overhead, Margin, +9 more · tier: internaOwner · Admin—
dealership_economics:write18 operations · Overhead, Cost Categories, Financial Institutions, +4 more · tier: internaOwner · Admin—
document_payments:read1 operation · Document payments · tier: betaOwner · Admin—
document_payments:write1 operation · Document payments · tier: betaOwner · Admin—
document_templates:read5 operations · Document Templates · tier: internaOwner · Admin—
document_templates:write5 operations · Document Templates · tier: internaOwner · Admin—
erp_copilot:use5 operations · ERP Copilot · tier: internaOwner · Admin · Supervisor · Agent—
followups:manage3 operations · Follow-ups · tier: internaOwner · Admin—
followups:read20 operations · Follow-ups, Vehicles · tier: beta and internaOwner · Admin · Supervisor · Agentconnector preset
followups:write22 operations · Follow-ups · tier: internaOwner · Admin · Supervisor · Agent—
functions:read5 operations · Functions, Custom tools · tier: beta and internaOwner · Admin—
functions:write9 operations · Custom tools, Functions · tier: beta and internaOwner · Admin—
healthatom:read17 operations · HealthAtom · tier: internaOwner · Admin—
healthatom:write10 operations · HealthAtom, Clinic caja · tier: internaOwner · Admin—
help_centers:read11 operations · Help centers · tier: betaOwner · Admin · Supervisor · Agentconnector preset
help_centers:write29 operations · Help centers · tier: betaOwner · Admin—
integrations:read4 operations · Integrations · Meta Ads · tier: beta and internaOwner · Admin—
integrations:write7 operations · Integrations · Meta Ads · tier: beta and internaOwner · Admin—
kb:read10 operations · Knowledge base — sources and indexed text, Knowledge base — files, AI agents · tier: betaOwner · Admin · Supervisor · Agent—
kb:write21 operations · Knowledge base — sources and indexed text, Knowledge base — files, AI agents · tier: betaOwner · Admin—
labels:read3 operations · Labels · tier: internaOwner · Admin · Supervisor · Agent—
labels:write5 operations · Labels · tier: internaOwner · Admin · Supervisor · Agent—
leads:intake2 operations · Public stock · tier: betaOwner · Adminpk_
leads:read10 operations · Leads · tier: betaOwner · Admin · Supervisor · Agentconnector preset
leads:write18 operations · Leads, Copilot · tier: beta and internaOwner · Admin · Supervisor · Agent—
legal:read2 operations · Legal · tier: internaOwner · Admin—
legal:write2 operations · Clinic caja, Legal · tier: internaOwnerowner only
macros:read5 operations · Macros · tier: beta and internaOwner · Admin · Supervisor · Agent—
macros:write3 operations · Macros · tier: betaOwner · Admin—
marketplace:read46 operations · Vehicles, Marketplaces, Instagram Media, +3 more · tier: beta and internaOwner · Admin · Supervisor · Agentconnector preset
marketplace:write43 operations · Marketplaces, Vehicles, Instagram Media, +2 more · tier: beta and internaOwner · Admin—
mcp:connectorNo API route requires it today—connector preset
mcp_servers:read2 operations · McpServers · tier: internaOwner · Admin—
mcp_servers:write3 operations · McpServers · tier: internaOwner · Admin—
memberships:read3 operations · Team · tier: betaOwner · Admin · Supervisor—
memberships:write6 operations · Team · tier: betaOwner · Admin—
messages:readNo API route requires it todayOwner · Admin · Supervisor · Agent—
messages:send8 operations · Conversations, Appointments · tier: betaOwner · Admin · Supervisor · Agent—
messages:write1 operation · Messages · tier: internaOwner · Admin—
messaging_accounts:read19 operations · MessagingAccounts, Channels, Messaging Accounts, +3 more · tier: beta and internaOwner · Admin—
messaging_accounts:write30 operations · MessagingAccounts, Messaging Accounts, Onboarding, +3 more · tier: beta and internaOwner · Admin—
organization_legal:read2 operations · Organization Legal · tier: internaOwner · Admin—
organization_legal:write3 operations · Organization Legal · tier: internaOwner · Admin—
outbound_approvals:read2 operations · Outbound approvals · tier: internaOwner · Admin—
outbound_approvals:write2 operations · Outbound approvals · tier: internaOwner · Admin—
outbound_holds:read3 operations · Safety holds · tier: internaOwner · Admin—
outbound_holds:write3 operations · Safety holds · tier: internaOwner · Admin—
payments:read7 operations · Charges and payments, Contacts · tier: betaOwner · Admin—
payments:reverse2 operations · Charges and payments · tier: betaOwner · Admin—
payments:write13 operations · Charges and payments, Clinic budgets, Contacts · tier: betaOwner · Admin—
personal_tokens:read1 operation · Personal tokens · tier: betaOwner · Admin · Supervisor · Agent—
personal_tokens:write2 operations · Personal tokens · tier: betaOwner · Admin · Supervisor · Agent—
pipelines:read6 operations · Pipelines · tier: beta and internaOwner · Admin · Supervisor · Agentconnector preset
pipelines:write6 operations · Pipelines · tier: beta and internaOwner · Admin—
price_approval:approve1 operation · Price approvals · tier: betaOwner · Admin—
price_approval:read2 operations · Price approvals · tier: betaOwner · Adminconnector preset
price_approval:request1 operation · Price approvals · tier: betaOwner · Admin—
pricing:read11 operations · Pricing · tier: internaOwner · Admin—
pricing:write6 operations · Pricing · tier: internaOwner · Admin—
provisioning:read3 operations · Provisioning · tier: internaOwner · Admin—
provisioning:write7 operations · Provisioning · tier: internaOwner · Admin—
purchase_notes:read2 operations · Purchase notes · tier: betaOwner · Admin—
purchase_notes:void1 operation · Purchase notes · tier: betaOwner · Admin—
purchase_notes:write2 operations · Purchase notes · tier: betaOwner · Admin—
quotes:read2 operations · Quotes · tier: betaOwner · Admin—
quotes:void1 operation · Quotes · tier: betaOwner · Admin—
quotes:write3 operations · Quotes · tier: betaOwner · Admin—
reservations:dispose_abono1 operation · Reservations · tier: betaOwner · Admin—
reservations:read2 operations · Reservations · tier: betaOwner · Admin—
reservations:void1 operation · Reservations · tier: betaOwner · Admin—
reservations:write1 operation · Reservations · tier: betaOwner · Admin—
reservo:read2 operations · Reservo · tier: internaOwner · Admin—
reservo:write5 operations · Reservo · tier: internaOwner · Admin—
rexplus:read2 operations · outside the published contractOwner · Admin—
rexplus:write4 operations · outside the published contractOwner · Admin—
roles:read2 operations · Custom roles · tier: betaOwner · Admin—
roles:write3 operations · Custom roles · tier: betaOwner · Admin—
routing:read3 operations · Assignment rules · tier: betaOwner · Admin—
routing:write5 operations · Assignment rules · tier: betaOwner · Admin—
sale_notes:read10 operations · Sale notes, Transfer Tax · tier: beta and internaOwner · Admin—
sale_notes:void1 operation · Sale notes · tier: betaOwner · Admin—
sale_notes:write9 operations · Sale notes, Reservations · tier: beta and internaOwner · Admin—
sales_leaderboard:read1 operation · Insights · tier: internaOwner · Admin—
sandbox:read3 operations · Sandbox · tier: betaOwner · Admin—
sandbox:write3 operations · Sandbox · tier: betaOwner · Admin—
schedule_config:write1 operation · Appointments · tier: betaOwner · Admin—
seller_compensation:read2 operations · Sale notes, Seller Compensation · tier: internaOwner · Admin—
seller_compensation:write2 operations · Sale notes, Seller Compensation · tier: internaOwner · Admin—
service_lifecycle:read6 operations · Service lifecycle · tier: internaOwner · Admin—
service_lifecycle:write11 operations · Service lifecycle · tier: internaOwner · Admin—
slas:read2 operations · SLAs · tier: betaOwner · Admin · Supervisor · Agent—
slas:write3 operations · SLAs · tier: betaOwner · Admin—
stages:read2 operations · Stages · tier: betaOwner · Admin · Supervisor · Agent—
stages:write5 operations · Stages · tier: betaOwner · Admin—
stock:read5 operations · Public stock · tier: betaOwner · Adminpk_
stock_dedup:read1 operation · Vehicles · tier: betaOwner · Admin—
stock_dedup:write1 operation · Vehicles · tier: betaOwner · Admin—
stock_photo_mirror:read1 operation · Vehicles · tier: betaOwner · Admin—
stock_photo_mirror:write2 operations · Vehicles · tier: betaOwner · Admin—
stock_retirement:read1 operation · Vehicles · tier: betaOwner · Admin—
stock_retirement:write1 operation · Vehicles · tier: betaOwner · Admin—
storefront_events:write2 operations · Public stock · tier: betaOwner · Adminpk_
tags:read4 operations · Tags, Conversations · tier: betaOwner · Admin · Supervisor · Agent—
tags:write5 operations · Tags, Conversations · tier: betaOwner · Admin · Supervisor · Agent—
teams:read3 operations · Teams · tier: betaOwner · Admin · Supervisor · Agentconnector preset
teams:write6 operations · Teams · tier: betaOwner · Admin · Supervisor—
tenant:deleteNo API route requires it todayOwnerowner only
tenant:read9 operations · Workspace settings, Locations, Digest, +1 more · tier: beta and internaOwner · Admin · Supervisor · Agentconnector preset
tenant:write19 operations · Workspace settings, Locations, Add-ons, +2 more · tier: beta and internaOwner · Admin—
tenant_bank_accounts:read2 operations · Bank Accounts · tier: internaOwner · Admin—
tenant_bank_accounts:write2 operations · Bank Accounts · tier: internaOwner · Admin—
tickets:claim1 operation · Tickets · tier: betaOwner · Admin · Supervisor · Agent—
tickets:read6 operations · Tickets · tier: betaOwner · Admin · Supervisor · Agentconnector preset
tickets:write7 operations · Tickets, Conversations, Copilot · tier: beta and internaOwner · Admin · Supervisor · Agent—
tool_credentials:read2 operations · Tool credentials · tier: betaOwner · Admin—
tool_credentials:write3 operations · Tool credentials · tier: betaOwner · Admin—
tool_invocations:read2 operations · outside the published contractOwner · Admin—
tools:read2 operations · Tools · tier: internaOwner · Admin · Supervisor · Agent—
transfer_cases:read3 operations · Transfer Cases · tier: internaOwner · Admin—
transfer_cases:write5 operations · Transfer Cases · tier: internaOwner · Admin—
triggers:read2 operations · Triggers · tier: betaOwner · Admin—
triggers:write3 operations · Triggers · tier: betaOwner · Admin—
vehicle_pipeline:read1 operation · Vehicles · tier: betaOwner · Admin · Supervisor · Agentconnector preset
vehicle_pipeline:write4 operations · Vehicles · tier: betaOwner · Admin · Supervisor · Agent—
vehicle_registry:read2 operations · Vehicle attachments · tier: betaOwner · Admin—
vehicle_registry:write2 operations · Vehicle attachments · tier: betaOwner · Admin—
voice_drift:read1 operation · outside the published contractOwner · Admin—
webhooks:read4 operations · Webhooks · tier: betaOwner · Admin—
webhooks:write5 operations · Webhooks · tier: betaOwner · Admin—
widget:chat4 operations · Widget · tier: interna—pk_
worker_failures:read2 operations · WorkerFailures · tier: internaOwner · Admin—
worker_failures:write2 operations · WorkerFailures · tier: internaOwner · Admin—

The connector preset

What the guided connect flow for a Connected app mints: one read permission per tool family the connector profile exposes, and nothing else. It is not a role, and no person carries it.

mcp:connector sits inside it, and it is not a permission: it guards no route, no tool, no field and no column. Its only effect is to take capability away from its bearer — the MCP server sees the marker and narrows its catalogue to a read-only profile — which is why it can travel in plain sight on the credential: there is nothing to escalate to. A credential carrying this marker and nothing else can do strictly less than a credential carrying nothing at all.

  • analytics:read
  • appointment_types:read
  • appointments:read
  • clinic:read
  • contacts:read
  • conversations:read
  • followups:read
  • help_centers:read
  • leads:read
  • marketplace:read
  • mcp:connector
  • pipelines:read
  • price_approval:read
  • teams:read
  • tenant:read
  • tickets:read
  • vehicle_pipeline:read

Margin and cost reading is not included: it is added by ticking the matching box while connecting, and without that scope those tools are absent from the catalogue rather than present and refusing.

Publishable pk_ keys

A pk_ key lives in the browser, so it carries no scopes of its own: the platform resolves this fixed set for it on every request. No role hands it out and the mint form does not offer it; a pk_ can never carry a broad write or an admin permission.

  • appointments:intake
  • leads:intake
  • stock:read
  • storefront_events:write
  • widget:chat

Adding an entry to this set grants it to every pk_ already in the wild, with no re-mint — which is why the list stays short and every entry opens exactly one public surface.

Deprecated spellings

A one-release bridge: a credential carrying the old string is treated as carrying the new one, and nothing else changes. The deprecated spelling cannot be handed out, no role offers it and the mint form will not take it — it only keeps working on the credentials that already had it.

Deprecated spellingTreated as
healthatom:readclinic:read
healthatom:writeclinic:write

On this page