Skip to content

Key permissions

A key's permissions are set per area, each at one of three levels. A new key holds none everywhere — it can do nothing until a person grants something on the API Keys page.

Level Allows
none nothing in this area — every request is refused with 403
view reading: GET
edit reading and changing: GET, POST, PUT, PATCH, DELETE
Area (scopes key) Shown in the web app as Governs
courses Courses /api/v1/agent/courses/
chapters Units (API: chapters) /api/v1/agent/courses/{id}/chapters/
lessons Lessons (incl. quizzes and assignments) …/chapters/{id}/lessons/
org_settings Organization settings /api/v1/agent/org-settings/

GET /api/v1/agent/whoami/ needs no permission and returns the key's current levels.

Permissions are checked on every request. A person can raise, lower or revoke them at any moment and the next request sees the change. An unknown or malformed permission is always treated as none.