Platform

API key scopes

Every API key scope and what it grants — generated from the contract source.

API keys carry explicit scopes; a request succeeds only when the key holds every scope the route requires. Keys are organization- or project-scoped, can expire, and their secrets (myna_sk_…) are shown once and stored only as hashes.

Scopes reach one product. Holding a scope for a product a project does not run is harmless — those routes answer PRODUCT_NOT_ENABLED.

Scope Grants
content:read Read entries and private collections, including drafts.
content:write Create and update draft entries.
content:delete Stage entry deletions on change sets.
content:publish Publish change sets. Withhold this from agent keys to keep a human in the loop.
content:restore Restore historical revisions into new drafts.
content:review Approve or request changes on a change set, and report external check results.
assets:read Read asset metadata.
assets:write Upload assets.
assets:delete Delete assets.
preview:write Create and revoke preview tokens.
schema:read Read collection schemas and versions.
schema:write Push schema changes.
feedback:read Read reports, their timelines, and their attachments.
feedback:write Reply to reports, triage them, and change their state.
feedback:manage Delete reports, moderate the spam queue, and change board settings.
webhooks:manage Manage webhook endpoints and deliveries.
project:admin Project settings and project-scoped keys. Covers Content only; it never widens to another product.
admin:all Everything, across every product. The only scope that covers products added later.

For agent keys, the recommended baseline is content:read, content:write, assets:read, assets:write, preview:write, and schema:read — everything needed to draft and preview, nothing that publishes.

A key may additionally be confined to specific collections, which is a second, independent limit: holding content:write says the key may write, and the confinement says what. When a call is refused, myna access --capability <scope> --collection <key> reports which of the two is missing — or whether the resource simply is not there. See Authentication.