Get started
REFERENCE

Scopes

A token carries scopes, and they do two things: gate the call, and gate discovery - a tool whose scope you do not hold is not listed at all. Grant the narrowest set that does the job.

No scope grants everything Around thirty tools are refused to agent principals whatever their token says: creating tenants, changing membership, registering agents, resolving decisions, and every hard delete. They are marked in the tool reference.
activity:read2 tools
activity:write1 tool
agents:read5 tools
agents:write4 tools
approvals:read1 tool
approvals:write2 tools
assets:read11 tools
assets:write13 tools
assignments:read2 tools
assignments:write2 tools
billing:read4 tools
credentials:reveal1 tool

Returns stored secrets in plaintext. Everything else in the product goes out of its way never to do this.

decisions:read7 tools
decisions:write16 tools
documents:read8 tools
documents:write5 tools
financials:read1 tool
financials:write1 tool
inbox:read2 tools
inbox:write1 tool
incidents:read2 tools
incidents:write2 tools
infra:read12 tools

Enumerates every server the ORGANIZATION runs, across all workspaces - strictly wider than any product-level read, which is why no product scope implies it.

infra:write16 tools
instructions:read8 tools
instructions:write11 tools
integrations:read3 tools
integrations:write6 tools
intelligence:read6 tools
inventory:read4 tools
inventory:write4 tools
invites:read1 tool
marketing:read3 tools
marketing:write3 tools
org_overview:read1 tool
orgs:read5 tools
orgs:write7 tools
products:read26 tools= projects:read
products:write29 tools= projects:write
profile:read1 tool
profile:write1 tool
projects:read2 tools= products:read
projects:write13 tools= products:write
resources:read2 tools
resources:write3 tools
setup_profiles:read5 tools
setup_profiles:write3 tools
site:read3 tools
site:write0 tools
tasks:read5 tools
tasks:write18 tools
workspace:export3 tools

Produces a bundle of the entire workspace in one call. Every other read is narrow; this one is not.

products:* and projects:* are equivalent - holding either satisfies the other. The projects spelling is the older name kept working; write new tokens with products.