API key scopes

Every Flint API key holds a set of scopes, and each endpoint checks for the scopes it needs. A key that lacks them gets 403 INSUFFICIENT_SCOPE. Grant each key the narrowest set its job needs.

To send a key, choose between test and live keys, or create and revoke keys over the API, see Authentication. For expiry, rotation, and leak response, see Key security.

Scope catalog#

The table is generated from the same catalog used by API key validation and the dashboard pickers.

Credentials and API keys

ScopePermissionKey modesPartner installs
accounts.api_keys.readRead api keyslive, testNot allowed
accounts.api_keys.writeWrite api keyslive, testNot allowed

Developer tools

ScopePermissionKey modesPartner installs
developer.partner_apps.readRead partner appsliveNot allowed
developer.partner_apps.writeWrite partner appsliveNot allowed
developer.sandboxes.readRead sandboxesliveNot allowed
developer.sandboxes.writeWrite sandboxesliveNot allowed
developer.feedback_reports.writeWrite feedback reportslive, testNot allowed
developer.feedback_reports.readRead feedback reportslive, testNot allowed

Merchant account

ScopePermissionKey modesPartner installs
merchants.profile.readRead merchant profilelive, testAllowed
merchants.profile.writeWrite merchant profilelive, testNot allowed
merchants.onboarding.readRead onboardinglive, testNot allowed
merchants.account_sessions.writeWrite merchant account sessionslive, testNot allowed
merchants.onboarding.writeWrite onboardinglive, testNot allowed
merchants.locations.readRead locationslive, testAllowed
merchants.locations.writeWrite locationslive, testAllowed
merchant_billing.readRead merchant billinglive, testNot allowed

Developer and account

ScopePermissionKey modesPartner installs
accounts.organizations.readRead organizationslive, testNot allowed
accounts.organizations.writeWrite organizationsliveNot allowed
settings.readRead settingslive, testNot allowed
settings.writeWrite settingslive, testNot allowed
accounts.devices.readRead deviceslive, testNot allowed
accounts.devices.writeWrite deviceslive, testNot allowed
analytics.readRead analyticslive, testAllowed
webhooks.readRead webhookslive, testAllowed
webhooks.writeWrite webhookslive, testAllowed
developer.request_logs.self.readRead own request logslive, testNot allowed
developer.request_logs.self.detail.readRead own request log detailslive, testNot allowed
developer.resource_timelines.readRead resource timelineslive, testNot allowed

Customers

ScopePermissionKey modesPartner installs
customers.readRead customerslive, testAllowed
customers.writeWrite customerslive, testAllowed
customers.sessions.writeWrite customer sessionslive, testNot allowed

Commerce

ScopePermissionKey modesPartner installs
commerce.products.readRead productslive, testAllowed
commerce.products.writeWrite productslive, testAllowed
commerce.orders.readRead orderslive, testAllowed
commerce.orders.writeWrite orderslive, testAllowed
commerce.refunds.readRead refundslive, testAllowed
commerce.refunds.writeWrite refundslive, testAllowed
commerce.subscription_plans.readRead subscription planslive, testAllowed
commerce.subscription_plans.writeWrite subscription planslive, testAllowed
commerce.subscriptions.readRead subscriptionslive, testAllowed
commerce.subscriptions.writeWrite subscriptionslive, testAllowed
commerce.invoices.readRead invoiceslive, testAllowed
commerce.invoices.writeWrite invoiceslive, testAllowed
commerce.bundles.readRead bundleslive, testAllowed
commerce.bundles.writeWrite bundleslive, testAllowed
commerce.catalog.readRead cataloglive, testAllowed
commerce.catalog.writeWrite cataloglive, testAllowed
commerce.refunds.tax_overrides.writeWrite refund tax overrideslive, testNot allowed
commerce.promotions.readRead promotionslive, testAllowed
commerce.promotions.writeWrite promotionslive, testAllowed
commerce.inventory.readRead inventorylive, testAllowed
commerce.inventory.writeWrite inventorylive, testAllowed
commerce.inventory_policies.writeWrite inventory policieslive, testAllowed
commerce.inventory_locations.writeWrite inventory location authoritylive, testAllowed
commerce.returns.readRead returnslive, testAllowed
commerce.returns.writeWrite returnslive, testAllowed
commerce.returns.operations.writeWrite return operationslive, testAllowed
commerce.returns.resolutions.writeWrite return resolutionslive, testAllowed
commerce.return_policies.writeWrite return policieslive, testAllowed
commerce.return_reasons.writeWrite return reasonslive, testAllowed
commerce.delivery.readRead deliverylive, testAllowed
commerce.delivery.writeWrite deliverylive, testAllowed
commerce.credit_notes.readRead credit noteslive, testAllowed
commerce.credit_notes.writeWrite credit noteslive, testAllowed
commerce.gift_cards.readRead gift cardslive, testAllowed
commerce.gift_cards.writeWrite gift cardslive, testAllowed
commerce.gift_cards.redemptions.writeWrite gift card redemptions and refundslive, testAllowed
commerce.gift_cards.adjustments.writeWrite gift card adjustments and cash-outslive, testAllowed
commerce.gift_cards.secrets.writeWrite gift card codes and recipient deliverylive, testAllowed

Payments

ScopePermissionKey modesPartner installs
checkouts.checkout_sessions.readRead checkout sessionslive, testAllowed
checkouts.checkout_sessions.writeWrite checkout sessionslive, testAllowed
payments.payment_intents.readRead payment intentslive, testAllowed
payments.payment_intents.writeWrite payment intentslive, testAllowed
payments.payment_methods.readRead payment methodslive, testAllowed
payments.payment_methods.writeWrite payment methodslive, testAllowed
checkouts.payment_links.readRead payment linkslive, testAllowed
checkouts.payment_links.writeWrite payment linkslive, testAllowed
payments.disputes.readRead disputeslive, testNot allowed
capabilities.readRead capabilitieslive, testNot allowed
payments.payment_options.readRead payment optionslive, testAllowed
payments.payment_method_domains.readRead payment method domainslive, testNot allowed
payments.payment_method_domains.writeWrite payment method domainslive, testNot allowed

Risk

ScopePermissionKey modesPartner installs
risk.readRead risk datalive, testAllowed
risk.reviews.writeWrite risk reviewslive, testAllowed
risk.controls.writeWrite risk controlslive, testAllowed

Money movement

ScopePermissionKey modesPartner installs
money_movement.balances.readRead balanceslive, testNot allowed
money_movement.balance_transactions.readRead balance transactionslive, testNot allowed
money_movement.payouts.readRead payoutslive, testNot allowed
money_movement.payouts.writeWrite payoutslive, testNot allowed
money_movement.payout_settings.readRead payout settingslive, testNot allowed
money_movement.payout_settings.writeWrite payout settingslive, testNot allowed
reports.readRead reportslive, testAllowed
reports.writeWrite reportslive, testAllowed

How scopes are evaluated#

A matching write scope satisfies its read scope. For example, commerce.orders.write satisfies a route requiring commerce.orders.read. A write scope does not satisfy reads for a sibling resource, and unqualified scopes do not imply qualified permissions such as commerce.refunds.tax_overrides.write.

all is reserved for trusted internal keys and cannot be granted to an external API key.

Returns use commerce.returns.write for requests and decisions, commerce.returns.operations.write for receiving and inspection work, and commerce.returns.resolutions.write for refunds, credits, and exchanges. POST /v1/returns/{return_id}/process requires all three. Gift card notifications and code replacement both use commerce.gift_cards.secrets.write.

Creating, committing, consuming, and releasing inventory reservations requires commerce.inventory.write. Managing a Location's inventory settings requires commerce.inventory_locations.write, so you can grant stock operations without permission to change where orders ship from or buyers pick up.

Payment scopes follow ownership, not resource type#

A payment intent that belongs to an order is authorized by the order's scopes, not by payments.payment_intents.write. The route you call decides the scope you need.

A key holding only payments.payment_intents.write receives INSUFFICIENT_SCOPE on every order-scoped payment route. The error's scope_requirement and missing_scopes fields name the exact missing authority.

Was this helpful?