Scopes & permissions
Give an integration only the access it needs.
Read and write scopes
Resource scopes use the form resource:read and resource:write. Write covers read. OAuth scopes are also restricted by the authorizing member’s role.
API keys and member access
An API key represents the workspace rather than a person. It can hold only scopes the workspace owner has without record-level restrictions. Some scopes are available only to OAuth tokens.
Check the operation
Each operation in the API reference lists its required scope. Verify the operation and the member’s permissions before requesting broader access.