Scopes
| Scope | Grants |
|---|---|
api:discovery | GET /v1 |
audit:read | Read your audit trail and verify its hash chain |
customers:read | Read customers and departments |
customers:write | Create/update customers and departments, and set the e-invoicing endpoint |
customerchecks:read | Read customer checks (AML/KYC), their parties and documentation |
customerchecks:write | Start a customer check and start a periodic review |
dispatches:read | Read dispatches, their delivery proof, and which channels are open |
properties:read | Read rental units, tenancies and portfolio areas |
properties:write | Create and update rental units and areas |
events:read | Read the event feed (GET /v1/events) |
finance:read | Read open items — what each customer owes you and how old it is |
invoices:read | Read invoices, PDFs and timelines |
invoices:write | Create drafts, issue, send, delete drafts |
members:read | Read members and the role catalogue |
members:manage | Assign member roles (privilege-escalation surface — grant sparingly) |
notifications:read | Read the organisation’s notifications and the type catalogue |
notifications:write | Acknowledge notifications (a receipt for your key, not for your colleagues) |
orders:read | Read orders, their invoices, timeline and confirmation PDF |
orders:write | Create, confirm, invoice, cancel orders; create orders from accepted quotes |
paymentplans:read | Read payment plans, what a customer may be offered, and the plan covering an invoice |
paymentplans:write | Propose and close payment plans (activation is the customer’s signature — never an API call) |
payments:read | Read payments and receipts |
payments:write | Register manual payments |
products:read | Read products and the chart of accounts |
products:write | Create/update products and accounts |
quotes:read | Read quotes, their attachments, timeline and quote PDF |
quotes:write | Create, send, delete draft quotes; attach documents; turn accepted quotes into orders or invoices |
reminders:read | Read reminder history and settings |
reminders:write | Send ad-hoc reminders, configure reminder settings and flows |
settings:read | Read organisation settings (numbering, tone, payment methods) |
settings:write | Write branding, payment domain and customer-portal settings |
subscriptions:read | Read subscriptions, their invoices and previews |
subscriptions:write | Create/update subscriptions, transitions, run now |
tasks:read | Read the task queue — including the approvals waiting for your yes |
tasks:write | Answer tasks: approve or decline a case start, collections, bailiff or lawsuit |
cases:read | Read collection cases |
cases:write | Create collection cases |
contracts:read | Read contracts, their parties, audit log, sealed PDF and your templates |
contracts:write | Create, send and cancel contracts — never sign them |
settlements:read | Read settlement history (GET /v1/settlements) |
terms:accept | Submit terms-acceptance evidence |
webhooks:manage | Administer webhook endpoints, rotate secrets, test, replay |
Grant a key only the scopes it needs.
Legacy scope names (sager:read, sager:write, afregninger:read, betingelse:accept)
remain valid as aliases on already-issued keys — new keys use the names above.