Orvelt
API reference

API-key permissions

Match each public operation to the permission required by its organization API key.

Match permissions to operations

Compare read and write access

The API key permission decides which resources an integration can read or change. The project in the request path must belong to the key's organization.

ResourceRead operationsWrite operations
storefrontGoals, questions, and platform goalsCreate, update, and delete goals or questions; update platform goals
reviewsReviews, opinions, answers, and sync endpointsOwner responses
preverifiedLinksList preverified linksCreate links and email invitations
qrCodesList QR credentials and display the current rotating credentialCreate a QR credential
subscribersList subscribersRemove a subscriber
knowledgebaseList knowledge-base itemsAdd, update, or delete an item
webhooksNoneOpen the portal or create/update a destination

Recover from a permission error

The API reference page for each operation shows its required permission. Ask an organization administrator to update a key when a request returns 403.

Project QR codes use the qrCodes permission. API keys can list and create credentials, and display the current rotating credential; regenerating or revoking a code remains a dashboard-only action.

Project scope

Keep the key and path aligned

Use the key's project ID in every /project/{projectId} path. A key cannot read or change another project's data, even when the caller knows that project's ID.