Scopes
A scope names a kind of access. Each credential is granted a set of scopes, and a token can carry that set or any smaller part of it. An endpoint answers 403 insufficient_scope when the token lacks a scope it needs.
:readscopes never change data.:writescopes may.- Some endpoints use POST only because they take a request body, such as searches and reports. They ask for a
:readscope, since they change nothing. - API keys hold every scope, so nothing changes for existing integrations.
- Endpoints that are not listed in the reference are not available to OAuth credentials.
| Scope | Allows | Operations |
|---|---|---|
company:read | Read company and location details, settings and loyalty programs | checkUsageLimit companyFormfields companyGetAccessibleCompanyIds companyGetChildLocation companyGetLoyaltyProgram getLocationsInfo and 1 more |
customers:read | Search and read customers and their history | customerSearch customerSearchByCellPhoneOrEmail customers customersByCompany customersHistory |
customers:write | Create and update customers | customerGetOrCreateCustomer customersPost |
catalog:read | Read products, categories, vendors, brands, taxes, discounts and stock | dictionary getBrandsByCompany getCategoriesByCompany getCategory getDiscountsByCompany getProductImage and 11 more |
catalog:write | Create, update and delete products, categories and vendors, and adjust stock | deleteProductService putCategory putProductService putVendor updateProductStock updateStockByProductSKU |
orders:read | Read orders | getOrder |
orders:write | Create, update and cancel orders | cancelOrder putOrder putOrderV2 updateOrderNumbers |
employees:write | Create employees and import schedules | employeeCreate employeeImportSchedules |
bookings:read | Read booking services, providers and availability | bookingBookingtime bookingGetserviceproviders bookingGetservices bookingGetstatus bookingSearchservicetime |
bookings:write | Create bookings | bookingCreate |
purchase_orders:read | Read purchase orders | po poAll |
purchase_orders:write | Create and delete purchase orders | poCreate poDelete |
reports:read | Run reports | customerAnalysisReport reportCashRegisters reportTicketsV1 reportTicketsV2 reportTimeClocks reportTimeClocksGet |
datadump:read | Bulk data dumps of orders, payments, taxes, items, discounts and customers | datadumpCustomersV1 datadumpCustomersV1FromDate datadumpCustomersV1FromDateForLocation datadumpOrderDiscountsV1 datadumpOrderDiscountsV1FromDate datadumpOrderDiscountsV1FromDateForLocation and 20 more |
imports:write | Bulk product imports | importProducts importProductsV2 |
messaging:read | Read SMS logs | getSmsLogs |
walkin:read | Read the walk-in queue, services, providers and schedules | walkinBookingAppointments walkinCompanyWorkinghours walkinEmployeeSchedules walkinQueue walkinSecondaryContacts walkinServiceProviders and 3 more |