API key scopes
Every Flint API key holds a set of scopes, and each endpoint checks for the scopes it needs. A key that lacks them gets 403 INSUFFICIENT_SCOPE. Grant each key the narrowest set its job needs.
To send a key, choose between test and live keys, or create and revoke keys over the API, see Authentication. For expiry, rotation, and leak response, see Key security.
Scope catalog#
The table is generated from the same catalog used by API key validation and the dashboard pickers.
Credentials and API keys
| Scope | Permission | Key modes | Partner installs |
|---|---|---|---|
accounts.api_keys.read | Read api keys | live, test | Not allowed |
accounts.api_keys.write | Write api keys | live, test | Not allowed |
Developer tools
| Scope | Permission | Key modes | Partner installs |
|---|---|---|---|
developer.partner_apps.read | Read partner apps | live | Not allowed |
developer.partner_apps.write | Write partner apps | live | Not allowed |
developer.sandboxes.read | Read sandboxes | live | Not allowed |
developer.sandboxes.write | Write sandboxes | live | Not allowed |
developer.feedback_reports.write | Write feedback reports | live, test | Not allowed |
developer.feedback_reports.read | Read feedback reports | live, test | Not allowed |
Merchant account
| Scope | Permission | Key modes | Partner installs |
|---|---|---|---|
merchants.profile.read | Read merchant profile | live, test | Allowed |
merchants.profile.write | Write merchant profile | live, test | Not allowed |
merchants.onboarding.read | Read onboarding | live, test | Not allowed |
merchants.account_sessions.write | Write merchant account sessions | live, test | Not allowed |
merchants.onboarding.write | Write onboarding | live, test | Not allowed |
merchants.locations.read | Read locations | live, test | Allowed |
merchants.locations.write | Write locations | live, test | Allowed |
merchant_billing.read | Read merchant billing | live, test | Not allowed |
Developer and account
| Scope | Permission | Key modes | Partner installs |
|---|---|---|---|
accounts.organizations.read | Read organizations | live, test | Not allowed |
accounts.organizations.write | Write organizations | live | Not allowed |
settings.read | Read settings | live, test | Not allowed |
settings.write | Write settings | live, test | Not allowed |
accounts.devices.read | Read devices | live, test | Not allowed |
accounts.devices.write | Write devices | live, test | Not allowed |
analytics.read | Read analytics | live, test | Allowed |
webhooks.read | Read webhooks | live, test | Allowed |
webhooks.write | Write webhooks | live, test | Allowed |
developer.request_logs.self.read | Read own request logs | live, test | Not allowed |
developer.request_logs.self.detail.read | Read own request log details | live, test | Not allowed |
developer.resource_timelines.read | Read resource timelines | live, test | Not allowed |
Customers
| Scope | Permission | Key modes | Partner installs |
|---|---|---|---|
customers.read | Read customers | live, test | Allowed |
customers.write | Write customers | live, test | Allowed |
customers.sessions.write | Write customer sessions | live, test | Not allowed |
Commerce
| Scope | Permission | Key modes | Partner installs |
|---|---|---|---|
commerce.products.read | Read products | live, test | Allowed |
commerce.products.write | Write products | live, test | Allowed |
commerce.orders.read | Read orders | live, test | Allowed |
commerce.orders.write | Write orders | live, test | Allowed |
commerce.refunds.read | Read refunds | live, test | Allowed |
commerce.refunds.write | Write refunds | live, test | Allowed |
commerce.subscription_plans.read | Read subscription plans | live, test | Allowed |
commerce.subscription_plans.write | Write subscription plans | live, test | Allowed |
commerce.subscriptions.read | Read subscriptions | live, test | Allowed |
commerce.subscriptions.write | Write subscriptions | live, test | Allowed |
commerce.invoices.read | Read invoices | live, test | Allowed |
commerce.invoices.write | Write invoices | live, test | Allowed |
commerce.bundles.read | Read bundles | live, test | Allowed |
commerce.bundles.write | Write bundles | live, test | Allowed |
commerce.catalog.read | Read catalog | live, test | Allowed |
commerce.catalog.write | Write catalog | live, test | Allowed |
commerce.refunds.tax_overrides.write | Write refund tax overrides | live, test | Not allowed |
commerce.promotions.read | Read promotions | live, test | Allowed |
commerce.promotions.write | Write promotions | live, test | Allowed |
commerce.inventory.read | Read inventory | live, test | Allowed |
commerce.inventory.write | Write inventory | live, test | Allowed |
commerce.inventory_policies.write | Write inventory policies | live, test | Allowed |
commerce.inventory_locations.write | Write inventory location authority | live, test | Allowed |
commerce.returns.read | Read returns | live, test | Allowed |
commerce.returns.write | Write returns | live, test | Allowed |
commerce.returns.operations.write | Write return operations | live, test | Allowed |
commerce.returns.resolutions.write | Write return resolutions | live, test | Allowed |
commerce.return_policies.write | Write return policies | live, test | Allowed |
commerce.return_reasons.write | Write return reasons | live, test | Allowed |
commerce.delivery.read | Read delivery | live, test | Allowed |
commerce.delivery.write | Write delivery | live, test | Allowed |
commerce.credit_notes.read | Read credit notes | live, test | Allowed |
commerce.credit_notes.write | Write credit notes | live, test | Allowed |
commerce.gift_cards.read | Read gift cards | live, test | Allowed |
commerce.gift_cards.write | Write gift cards | live, test | Allowed |
commerce.gift_cards.redemptions.write | Write gift card redemptions and refunds | live, test | Allowed |
commerce.gift_cards.adjustments.write | Write gift card adjustments and cash-outs | live, test | Allowed |
commerce.gift_cards.secrets.write | Write gift card codes and recipient delivery | live, test | Allowed |
Payments
| Scope | Permission | Key modes | Partner installs |
|---|---|---|---|
checkouts.checkout_sessions.read | Read checkout sessions | live, test | Allowed |
checkouts.checkout_sessions.write | Write checkout sessions | live, test | Allowed |
payments.payment_intents.read | Read payment intents | live, test | Allowed |
payments.payment_intents.write | Write payment intents | live, test | Allowed |
payments.payment_methods.read | Read payment methods | live, test | Allowed |
payments.payment_methods.write | Write payment methods | live, test | Allowed |
checkouts.payment_links.read | Read payment links | live, test | Allowed |
checkouts.payment_links.write | Write payment links | live, test | Allowed |
payments.disputes.read | Read disputes | live, test | Not allowed |
capabilities.read | Read capabilities | live, test | Not allowed |
payments.payment_options.read | Read payment options | live, test | Allowed |
payments.payment_method_domains.read | Read payment method domains | live, test | Not allowed |
payments.payment_method_domains.write | Write payment method domains | live, test | Not allowed |
Risk
| Scope | Permission | Key modes | Partner installs |
|---|---|---|---|
risk.read | Read risk data | live, test | Allowed |
risk.reviews.write | Write risk reviews | live, test | Allowed |
risk.controls.write | Write risk controls | live, test | Allowed |
Money movement
| Scope | Permission | Key modes | Partner installs |
|---|---|---|---|
money_movement.balances.read | Read balances | live, test | Not allowed |
money_movement.balance_transactions.read | Read balance transactions | live, test | Not allowed |
money_movement.payouts.read | Read payouts | live, test | Not allowed |
money_movement.payouts.write | Write payouts | live, test | Not allowed |
money_movement.payout_settings.read | Read payout settings | live, test | Not allowed |
money_movement.payout_settings.write | Write payout settings | live, test | Not allowed |
reports.read | Read reports | live, test | Allowed |
reports.write | Write reports | live, test | Allowed |
How scopes are evaluated#
A matching write scope satisfies its read scope. For example, commerce.orders.write satisfies a route requiring commerce.orders.read. A write scope does not satisfy reads for a sibling resource, and unqualified scopes do not imply qualified permissions such as commerce.refunds.tax_overrides.write.
all is reserved for trusted internal keys and cannot be granted to an external API key.
Returns use commerce.returns.write for requests and decisions, commerce.returns.operations.write for receiving and inspection work, and commerce.returns.resolutions.write for refunds, credits, and exchanges. POST /v1/returns/{return_id}/process requires all three. Gift card notifications and code replacement both use commerce.gift_cards.secrets.write.
Creating, committing, consuming, and releasing inventory reservations requires commerce.inventory.write. Managing a Location's inventory settings requires commerce.inventory_locations.write, so you can grant stock operations without permission to change where orders ship from or buyers pick up.
Payment scopes follow ownership, not resource type#
A payment intent that belongs to an order is authorized by the order's scopes, not by payments.payment_intents.write. The route you call decides the scope you need.
A key holding only payments.payment_intents.write receives INSUFFICIENT_SCOPE on every order-scoped payment route. The error's scope_requirement and missing_scopes fields name the exact missing authority.
