Each key carries a list of scopes, shaped resource:read or resource:write. Each operation requires one; a key without it gets 403 insufficient_scope and nothing runs.
The 14 scopes
write does not include read: an integration that creates contents and reads them back asks for contents:write and contents:read. generations:write is the only scope that uses AI credits; following its jobs takes jobs:read.
Choosing a key’s scopes
Scopes are set when the key is created, with our team: tell us which ones each integration needs. To change them, a new key is created with the right scopes, then the old one is revoked.
The 403 insufficient_scope refusal
details.required gives the required scope, details.granted those of the key:
{
"error": {
"code": "insufficient_scope",
"message": "This API key lacks the scope required by this operation (see `details.required`).",
"details": {
"required": "memocards:write",
"granted": [
"contents:read",
"memocards:read"
]
}
}
}