Permissions
What a credential is allowed to do.
DraftDescribes the intended design. Not yet available — names, fields and behaviour may change.
Permissions control what an API key or agent credential can do. They are separate from the roles people hold inside an account — see Members & Roles and Account Permissions.
A request succeeds only if both allow it:
- The credential has the permission for the action (for example, read balances or create payments).
- The account the request acts on allows that caller to perform the action, within its limits.
Guidance
- Prefer read-only credentials for dashboards, reporting, and monitoring.
- Give agents and machines explicit, narrow permissions and spending limits. See Agent Account.
- Review permissions before going live.
The permission catalogue will be published in the API Reference.
Last updated on