API reference
API-key permissions
Match each public operation to the permission required by its organization API key.
Match permissions to operations
Compare read and write access
The API key permission decides which resources an integration can read or change. The project in the request path must belong to the key's organization.
| Resource | Read operations | Write operations |
|---|---|---|
storefront | Goals, questions, and platform goals | Create, update, and delete goals or questions; update platform goals |
reviews | Reviews, opinions, answers, and sync endpoints | Owner responses |
preverifiedLinks | List preverified links | Create links and email invitations |
qrCodes | List QR credentials and display the current rotating credential | Create a QR credential |
subscribers | List subscribers | Remove a subscriber |
knowledgebase | List knowledge-base items | Add, update, or delete an item |
webhooks | None | Open the portal or create/update a destination |
Recover from a permission error
The API reference page for each operation shows its required permission. Ask an organization administrator to update a key when a request returns 403.
Project QR codes use the qrCodes permission. API keys can list and create credentials, and display the current rotating credential;
regenerating or revoking a code remains a dashboard-only action.
Project scope
Keep the key and path aligned
Use the key's project ID in every /project/{projectId} path. A key cannot read or change another project's data, even when the caller knows that project's ID.