Scopes: what a key may do

The 14 scopes of the Memojin API (contents:read, generations:write…), the operations each one opens, and the 403 insufficient_scope error.

api.memojin.com/v1 · Contract 1.0.0-beta.2 · Beta

Sections · Scopes

Each key carries a list of scopes, shaped resource:read or resource:write. Each operation requires one; a key without it gets 403 insufficient_scope and nothing runs.

The 14 scopes

ScopeAllowsOperations
contents:readRead contents.GET /v1/contentsGET /v1/contents/{contentId}
contents:writeCreate, update and delete contents.POST /v1/contentsPATCH /v1/contents/{contentId}DELETE /v1/contents/{contentId}
folders:readRead folders.GET /v1/foldersGET /v1/folders/{folderId}
folders:writeCreate, update and delete folders.POST /v1/foldersPATCH /v1/folders/{folderId}DELETE /v1/folders/{folderId}
memocards:readRead memocards.GET /v1/contents/{contentId}/memocardsGET /v1/memocards/{memocardId}
memocards:writeCreate, update and delete memocards.POST /v1/contents/{contentId}/memocardsPATCH /v1/memocards/{memocardId}DELETE /v1/memocards/{memocardId}
questions:readRead questions.GET /v1/contents/{contentId}/questionsGET /v1/questions/{questionId}
questions:writeCreate, update and delete questions.POST /v1/contents/{contentId}/questionsPATCH /v1/questions/{questionId}DELETE /v1/questions/{questionId}
generations:writeStart AI generations (uses AI credits).POST /v1/contents/{contentId}/memocard-generationsPOST /v1/contents/{contentId}/question-generations
jobs:readFollow asynchronous jobs.GET /v1/jobs/{jobId}
search:readSearch the library.GET /v1/search
spaces:readRead the spaces (classes, groups).GET /v1/spacesGET /v1/spaces/{spaceId}
study-sessions:readRead the study sessions.GET /v1/study-sessions
learning-stats:readRead the learning statistics.GET /v1/learning-stats

write does not include read: an integration that creates contents and reads them back asks for contents:write and contents:read. generations:write is the only scope that uses AI credits; following its jobs takes jobs:read.

Choosing a key’s scopes

Scopes are set when the key is created, with our team: tell us which ones each integration needs. To change them, a new key is created with the right scopes, then the old one is revoked.

The 403 insufficient_scope refusal

details.required gives the required scope, details.granted those of the key:

Response 403
{
  "error": {
    "code": "insufficient_scope",
    "message": "This API key lacks the scope required by this operation (see `details.required`).",
    "details": {
      "required": "memocards:write",
      "granted": [
        "contents:read",
        "memocards:read"
      ]
    }
  }
}