Skip to main content
Every API key carries a set of scopes that determine which endpoints it can call. Scopes follow the pattern resource:action - for example, sessions:read allows listing and viewing sessions but not modifying them.

Scope reference

Scopes by CLI operation

The same mapping, keyed by runtm-api command. Role gates are noted where a scope alone is not enough.

Scope presets

When creating a key in the dashboard, you can pick a preset instead of selecting individual scopes:
Start with the narrowest preset that fits your use case. You can always create a new key with more scopes later.

Role ceilings

A key can never exceed the permissions of the user who created it. The user’s organization role acts as a ceiling: If a user’s role is downgraded after a key is created, the key’s effective permissions are reduced to match the new role at request time.

Checking scopes at runtime

Use the Verify endpoint to inspect a key’s scopes programmatically:
The response includes a scopes array you can check before making further calls.

Insufficient scope errors

If a request requires a scope the key does not have, the API returns 403:
See Errors for the full error reference.