Key permissions¶
A key's permissions are set per area, each at one of three levels. A new key holds
none everywhere — it can do nothing until a person grants something on the
API Keys page.
| Level | Allows |
|---|---|
none |
nothing in this area — every request is refused with 403 |
view |
reading: GET |
edit |
reading and changing: GET, POST, PUT, PATCH, DELETE |
Area (scopes key) |
Shown in the web app as | Governs |
|---|---|---|
courses |
Courses | /api/v1/agent/courses/ |
chapters |
Units (API: chapters) | /api/v1/agent/courses/{id}/chapters/ |
lessons |
Lessons (incl. quizzes and assignments) | …/chapters/{id}/lessons/ |
org_settings |
Organization settings | /api/v1/agent/org-settings/ |
GET /api/v1/agent/whoami/ needs no permission and returns the key's current levels.
Permissions are checked on every request. A person can raise, lower or revoke
them at any moment and the next request sees the change. An unknown or malformed
permission is always treated as none.