Skip to content

Scopes

ScopeGrants
api:discoveryGET /v1
customers:readRead customers and departments
customers:writeCreate/update customers and departments
events:readRead the event feed (GET /v1/events)
invoices:readRead invoices, PDFs and timelines
invoices:writeCreate drafts, issue, send, delete drafts
members:readRead members and the role catalogue
members:manageAssign member roles (privilege-escalation surface — grant sparingly)
payments:readRead payments and receipts
payments:writeRegister manual payments
products:readRead products and the chart of accounts
products:writeCreate/update products and accounts
reminders:readRead reminder history and settings
reminders:writeSend ad-hoc reminders, configure reminder settings and flows
settings:readRead organisation settings (numbering, tone, payment methods)
settings:writeWrite branding, payment domain and customer-portal settings
subscriptions:readRead subscriptions, their invoices and previews
subscriptions:writeCreate/update subscriptions, transitions, run now
cases:readRead collection cases
cases:writeCreate collection cases
settlements:readRead settlement history (GET /v1/settlements)
terms:acceptSubmit terms-acceptance evidence
webhooks:manageAdminister webhook endpoints, rotate secrets, test, replay

Grant a key only the scopes it needs.

Legacy scope names (sager:read, sager:write, afregninger:read, betingelse:accept) remain valid as aliases on already-issued keys — new keys use the names above.