Scopes explained
Scopes are the only thing narrowing an API key. They are chosen when the key is created, in the portal, and a key can only do what its scopes allow. An empty scope list grants nothing.
There are six, in read/write pairs across three areas:
opportunities:readandopportunities:writecover reading matched solicitations, and sending feedback on them.profile:readandprofile:writecover the company profile, product catalog, and certifications.settings:readandsettings:writecover the digest schedule, recipients, and learned decision rules.
The live vocabulary is served from GET /api/v1/scopes, which is public. You
can read it without a credential:
curl https://app.prokure.ca/api/v1/scopesFinding the scope a route needs
Section titled “Finding the scope a route needs”The API tells you rather than making you guess. Call the route with the key you
have; if it is missing a scope, the response is 403 insufficient_scope and the
message names what was missing.
Scopes are fixed at creation. If an integration grows into needing a wider set, create a new key with it, deploy that, and revoke the old one.
Pick the narrowest set
Section titled “Pick the narrowest set”A dashboard that only displays opportunities wants opportunities:read and
nothing else. Adding profile:write to it buys nothing and widens what a leak
would cost you.
Related
Section titled “Related”- Authentication & API keys: what each scope grants, in full.
- List scopes.
- Best practices.