Scopes

A scope is one thing a key or a connected app is allowed to do. An admin picks a key's scopes when they create it; a connected app asks for scopes when someone connects it.

A call needs the scope its endpoint names, and the user the credential acts as still needs a role that allows the action in the app. A missing scope is refused with ERR_SCOPE_MISSING.

Connected apps that sign in through OAuth, including MCP clients, can be granted only the scopes marked so below, and meta:read is always included. These are for API keys only: leads:write, schema:read, usage:read and webhooks:manage.

All scopes

Scope Allows Connected apps
meta:read Statuses, departments, custom fields, forms, folders, the team list and other lookups. Always granted
leads:write Create leads. Kept for keys from the first release; jobs:write includes it. API keys only
schema:read The first release's name for meta:read. API keys only
jobs:read Read jobs, leads and opportunities. Can be granted
jobs:write Create and update jobs and leads, change status, convert and mark lost. Can be granted
contacts:read Read contacts. Can be granted
contacts:write Add contacts to jobs and update them. Can be granted
tasks:read Read tasks. Can be granted
tasks:write Create, update, complete and reopen tasks. Can be granted
notes:read Read job notes. Can be granted
notes:write Add job notes. Can be granted
calendar:read Read calendar events. Can be granted
calendar:write Create, change and delete calendar events. Can be granted
estimates:read Read estimates with their sections and lines. Can be granted
estimates:write Draft and edit estimates, and send them by email. Can be granted
invoices:read Read invoices and their payments. Can be granted
invoices:write Draft and edit invoices, and send them by email. Can be granted
files:read List job files and get download links. Can be granted
files:write Upload job files through signed upload links. Can be granted
comms:send Email a job's contacts from the acting user's connected mailbox. Can be granted
work_orders:read Read work orders. Can be granted
work_orders:write Create work orders and change their status. Can be granted
materials:read Read materials, stock items and job materials. Can be granted
materials:write Change stock items and job materials. Can be granted
purchasing:read Read vendors and purchase orders. Can be granted
purchasing:write Create vendors and purchase orders, add lines and receive stock. Can be granted
products:read Read products. Can be granted
products:write Create and update products. Can be granted
time:read Read time entries. Can be granted
usage:read This account's call usage and limits. API keys only
webhooks:manage Create and manage webhook endpoints and see deliveries. API keys only

Endpoints by scope

meta:read

Statuses, departments, custom fields, forms, folders, the team list and other lookups.

Endpoint What it does
GET /v1/account Check your credentials
GET /v1/custom-fields List the account's job fields
GET /v1/job-forms List the account's job forms
GET /v1/job-forms/{form_id} Get one job form
GET /v1/meta/custom-fields List the account's job fields
GET /v1/meta/departments List departments
GET /v1/meta/estimate-statuses List estimate statuses
GET /v1/meta/invoice-statuses List invoice statuses
GET /v1/meta/job-forms List the account's job forms
GET /v1/meta/job-statuses List job statuses
GET /v1/meta/material-types List material types
GET /v1/meta/product-categories List product categories
GET /v1/meta/task-statuses List task statuses
GET /v1/meta/units List units of measure
GET /v1/meta/users List the account's users
GET /v1/meta/work-order-types List work order types and their statuses
GET /v1/webhook-event-types List webhook event types

leads:write

Create leads. Kept for keys from the first release; jobs:write includes it.

Endpoint What it does
POST /v1/leads/create Create a lead

schema:read

The first release's name for meta:read.

No endpoint names this scope directly.

jobs:read

Read jobs, leads and opportunities.

Endpoint What it does
GET /v1/jobs List jobs
GET /v1/jobs/{job_id} Get a job

jobs:write

Create and update jobs and leads, change status, convert and mark lost.

Endpoint What it does
POST /v1/jobs Create a job
PATCH /v1/jobs/{job_id} Update a job
POST /v1/jobs/{job_id}/convert-to-project Convert an opportunity into a job
POST /v1/jobs/{job_id}/move-to-lost Mark a lead or opportunity lost
POST /v1/jobs/{job_id}/status Move a job to a status

contacts:read

Read contacts.

Endpoint What it does
GET /v1/contacts List contacts
GET /v1/contacts/{contact_id} Get a contact

contacts:write

Add contacts to jobs and update them.

Endpoint What it does
PATCH /v1/contacts/{contact_id} Update a contact
POST /v1/jobs/{job_id}/contacts Add a contact to a job

tasks:read

Read tasks.

Endpoint What it does
GET /v1/jobs/{job_id}/tasks List a job's tasks
GET /v1/tasks/{task_id} Get a task

tasks:write

Create, update, complete and reopen tasks.

Endpoint What it does
POST /v1/jobs/{job_id}/tasks Add a task to a job
PATCH /v1/tasks/{task_id} Update a task
POST /v1/tasks/{task_id}/complete Complete a task
POST /v1/tasks/{task_id}/reopen Reopen a task

notes:read

Read job notes.

Endpoint What it does
GET /v1/jobs/{job_id}/notes List a job's notes
GET /v1/jobs/{job_id}/threads List a job's threads

notes:write

Add job notes.

Endpoint What it does
POST /v1/jobs/{job_id}/notes Add a note to a job

calendar:read

Read calendar events.

Endpoint What it does
GET /v1/calendar/events List events in a date range
GET /v1/calendar/events/{event_id} Get an event

calendar:write

Create, change and delete calendar events.

Endpoint What it does
POST /v1/calendar/events Create an event
DELETE /v1/calendar/events/{event_id} Delete an event
PATCH /v1/calendar/events/{event_id} Update an event

estimates:read

Read estimates with their sections and lines.

Endpoint What it does
GET /v1/estimates List estimates
GET /v1/estimates/{estimate_id} Get an estimate

estimates:write

Draft and edit estimates, and send them by email.

invoices:read

Read invoices and their payments.

Endpoint What it does
GET /v1/invoices List invoices
GET /v1/invoices/{invoice_id} Get an invoice
GET /v1/invoices/{invoice_id}/payments List an invoice's payments
GET /v1/payments List payments

invoices:write

Draft and edit invoices, and send them by email.

Endpoint What it does
POST /v1/invoices Create a blank invoice
POST /v1/invoices/from-estimate/{estimate_id} Invoice an estimate
PATCH /v1/invoices/{invoice_id} Update a draft invoice
PATCH /v1/invoices/{invoice_id}/lines/{line_id} Update an invoice line
POST /v1/invoices/{invoice_id}/sections Add a section to an invoice
POST /v1/invoices/{invoice_id}/sections/{section_id}/lines Add a line to an invoice
POST /v1/invoices/{invoice_id}/send Email an invoice to contacts

files:read

List job files and get download links.

Endpoint What it does
GET /v1/files/{file_id} Get a file
GET /v1/jobs/{job_id}/files List a job's files

files:write

Upload job files through signed upload links.

Endpoint What it does
POST /v1/files/complete Finish an upload
POST /v1/jobs/{job_id}/files/upload-url Start an upload

comms:send

Email a job's contacts from the acting user's connected mailbox.

Endpoint What it does
POST /v1/jobs/{job_id}/emails Email a job's contacts

work_orders:read

Read work orders.

Endpoint What it does
GET /v1/work-orders List work orders
GET /v1/work-orders/{work_order_id} Get a work order

work_orders:write

Create work orders and change their status.

Endpoint What it does
POST /v1/work-orders Create a work order
PATCH /v1/work-orders/{work_order_id} Update a work order
POST /v1/work-orders/{work_order_id}/status Move a work order to a step

materials:read

Read materials, stock items and job materials.

Endpoint What it does
GET /v1/jobs/{job_id}/bom Get a job's bill of materials
GET /v1/materials List materials
GET /v1/materials/{material_id} Get a material
GET /v1/stock-items/{item_id} Get a stock item

materials:write

Change stock items and job materials.

Endpoint What it does
POST /v1/jobs/{job_id}/bom/lines Add a bill of materials line
DELETE /v1/jobs/{job_id}/bom/lines/{line_id} Remove a bill of materials line
PATCH /v1/jobs/{job_id}/bom/lines/{line_id} Update a bill of materials line

purchasing:read

Read vendors and purchase orders.

Endpoint What it does
GET /v1/purchase-orders List purchase orders
GET /v1/purchase-orders/{po_id} Get a purchase order
GET /v1/vendors List suppliers
GET /v1/vendors/{vendor_id} Get a supplier

purchasing:write

Create vendors and purchase orders, add lines and receive stock.

Endpoint What it does
POST /v1/purchase-orders Create a purchase order
PATCH /v1/purchase-orders/{po_id} Update a purchase order
POST /v1/purchase-orders/{po_id}/lines Add a purchase order line
PATCH /v1/purchase-orders/{po_id}/lines/{line_id} Update a purchase order line
POST /v1/purchase-orders/{po_id}/receive Record a delivery
POST /v1/vendors Create a supplier
PATCH /v1/vendors/{vendor_id} Update a supplier

products:read

Read products.

Endpoint What it does
GET /v1/products List products
GET /v1/products/{product_id} Get a product

products:write

Create and update products.

Endpoint What it does
POST /v1/products Create a product
PATCH /v1/products/{product_id} Update a product

time:read

Read time entries.

Endpoint What it does
GET /v1/time-entries List time entries

usage:read

This account's call usage and limits.

Endpoint What it does
GET /v1/account/usage See this account's API usage Needs an admin.

webhooks:manage

Create and manage webhook endpoints and see deliveries.

Endpoint What it does
GET /v1/webhook-deliveries/{delivery_id} Get a delivery Needs an admin.
POST /v1/webhook-deliveries/{delivery_id}/retry Retry a failed delivery Needs an admin.
GET /v1/webhooks List webhook endpoints Needs an admin.
POST /v1/webhooks Add a webhook endpoint Needs an admin.
DELETE /v1/webhooks/{endpoint_id} Delete a webhook endpoint Needs an admin.
GET /v1/webhooks/{endpoint_id} Get a webhook endpoint Needs an admin.
PATCH /v1/webhooks/{endpoint_id} Change a webhook endpoint Needs an admin.
GET /v1/webhooks/{endpoint_id}/deliveries List an endpoint's deliveries Needs an admin.
POST /v1/webhooks/{endpoint_id}/rotate-secret Rotate a webhook signing secret Needs an admin.
POST /v1/webhooks/{endpoint_id}/test Send a test event Needs an admin.