Skip to content

Scopes explained

Scopes are the only thing narrowing an API key. They are chosen when the key is created, in the portal, and a key can only do what its scopes allow. An empty scope list grants nothing.

There are six, in read/write pairs across three areas:

  • opportunities:read and opportunities:write cover reading matched solicitations, and sending feedback on them.
  • profile:read and profile:write cover the company profile, product catalog, and certifications.
  • settings:read and settings:write cover the digest schedule, recipients, and learned decision rules.

The live vocabulary is served from GET /api/v1/scopes, which is public. You can read it without a credential:

Terminal window
curl https://app.prokure.ca/api/v1/scopes

The API tells you rather than making you guess. Call the route with the key you have; if it is missing a scope, the response is 403 insufficient_scope and the message names what was missing.

Scopes are fixed at creation. If an integration grows into needing a wider set, create a new key with it, deploy that, and revoke the old one.

A dashboard that only displays opportunities wants opportunities:read and nothing else. Adding profile:write to it buys nothing and widens what a leak would cost you.