Octopus
Octopus Developersgateway.octopusoperations.co.za/v1

Guides

Scopes & permissions

A scope is the whole of a key's authority. A key is not a person: it holds no job title and inherits nothing.

Read and manage

Scopes come in pairs. .read lets you look; .manage lets you change. Asking for a .manage scope also grants the matching .read, tick tasks.manage and the key is created holding tasks.manage and tasks.read.

Ask for the least you need

Scopes are fixed when the key is made. If your integration only files tasks, ask for tasks.manage and nothing else. A leaked key is then worth almost nothing, and the customer can see exactly what you can touch.

What happens to a request

Three gates, all failing closed
Drawing…

The middle gate is the one integrators forget. An organisation can have a whole product module switched off, and then no key of theirs reaches it regardless of scopes. That is a plan and configuration fact, not a permissions mistake: the fix is in the organisation's subscription, not in your code.

A refusal names what it wanted

Scope failures are machine-readable, so your client can log which permission to ask the customer for rather than a generic “forbidden”:

Response · 403
{
  "success": false,
  "error": "This key does not have the \"clients.read\" scope.",
  "code": "scope_required",
  "requiredScope": "clients.read",
  "version": "v1"
}

A 403 with no requiredScope is the module gate, not the scope gate. Treat the two differently: one is fixed by issuing a new key, the other by the customer changing plan.

Every scope

ScopeGrants
organisation.readThe organisation record.
projects.readProjects, milestones, risks and issues.
projects.manageCreate and change projects and milestones.
tasks.readTasks and their comments.
tasks.manageCreate, change, delete and comment on tasks.
calendar.readEvents and repeating series.
calendar.manageAdd, change and cancel events.
clients.readClients.
clients.manageCreate and change clients.
personnel.readPeople, groups, certificates and compliance.
personnel.manageAdd and change people.
documents.readDocuments and download URLs.
documents.manageUpload and change documents.
financials.readFinancial entries and totals.
financials.manageAdd financial entries.
assets.readAssets and allocations.
assets.manageChange assets and allocations.
webhooks.manageRegister and manage webhook endpoints.