Skip to main content

Scopes

A scope grants a key access to one area of the API. Give each key only the scopes it needs.

A scope only works while the key's owner holds the DMS permission behind it. When the DMS creates a key, you can only grant scopes that you hold yourself.

ScopeWhat it allowsOwner needsPersonal data
vehicles:readRead vehicles and their imagesstock.viewNo
vehicles:writeCreate, update, delete and change the status of vehicles; upload and order images; batch uploadstock.manageNo
branches:readRead branchesNothingNo
enquiries:readRead enquiriesenquiries.viewYes
enquiries:writeCreate and update enquiries, add notesenquiries.manageYes
enquiries:deleteDelete enquiriesenquiries.deleteYes
customers:readRead customerscustomers.viewYes
customers:writeCreate and update customerscustomers.manageYes
customers:deleteDelete customers (soft delete)customers.deleteYes
sales:readRead deals, invoices and paymentsenquiries.viewYes
sales:writeChange a deal's statusenquiries.manageYes
appointments:readRead appointmentscalendar.viewYes
appointments:writeCreate, update and cancel appointmentscalendar.view and enquiries.manageYes
workshop:readRead workshop job cardsworkshop.viewYes
workshop:writeCreate and update job cardsworkshop.manageYes
part_exchanges:readRead part exchangespart_exchanges.manageNo
part_exchanges:writeCreate part exchangespart_exchanges.manageNo
users:readRead staff usersNothingNo (staff names and emails)
webhooks:manageCreate and manage webhook endpointsintegrations.manageNo
website_themes:readRead website theme builds and versionswebsite.themeNo
website_themes:writeRequest website theme builds and publish theme versionswebsite.themeNo
events:readRead the event logNothing, but events are filtered by the key's other scopesFollows the event

GET /v1/me and GET /v1/reference/{list} work with any key and any scope. The MCP server needs no scope of its own, but each of its tools is offered only to a key that has that tool's scope.

Personal data​

Scopes marked as reaching personal data return information about the dealer's customers. If your integration handles them, you are processing that data on the dealer's behalf: store only what you need and keep it secure.

Publishable keys​

Publishable keys have a fixed set that cannot be changed:

ScopeAllows
vehicles:readPublic vehicle fields, website-visible stock only
branches:readBranches
public:enquiriesPOST /v1/public/enquiries
public:valuation_requestsPOST /v1/public/valuation-requests

Events and scopes​

events:read returns only events the key could otherwise see, and a branch-restricted key sees only events about its branches or about no branch. Each event family needs a matching scope:

Event typesScope needed
vehicle.*vehicles:read
vehicle_batch.*vehicles:write
enquiry.*enquiries:read
customer.*customers:read
deal.*sales:read
appointment.*appointments:read
job_card.*workshop:read
theme_generation.*website_themes:read

Errors​

A request to an endpoint whose scope the key lacks is refused with 403 insufficient_scope. A key that has the scope but whose owner lost the permission gets 403 scope_not_permitted_for_owner.