resource:action - for example, sessions:read allows listing and viewing sessions but not modifying them.
Scope reference
Scopes by CLI operation
The same mapping, keyed byruntm-api command. Role gates are noted where a scope alone is not enough.
Scope presets
When creating a key in the dashboard, you can pick a preset instead of selecting individual scopes:Role ceilings
A key can never exceed the permissions of the user who created it. The user’s organization role acts as a ceiling:
If a user’s role is downgraded after a key is created, the key’s effective permissions are reduced to match the new role at request time.
Checking scopes at runtime
Use the Verify endpoint to inspect a key’s scopes programmatically:scopes array you can check before making further calls.
Insufficient scope errors
If a request requires a scope the key does not have, the API returns403: