PlayaOS Developer Docs

Scopes

API key permissions — what each scope grants access to.

Overview

API keys are permission-scoped. When you create a key, you choose which scopes to enable. A request to an endpoint that requires a scope your key doesn't have returns 403 Insufficient Scope.

Available Scopes

ScopeGrants access to
applications:readRead camp applications
applications:writeManage camp applications
audit:readRead audit logs
bookkeeping:readRead bookkeeping records
budget:readRead camp budget
checkins:readRead member check-ins
checkins:writeManage member check-ins
documents:readRead camp documents and signatures
documents:writeManage camp documents and signatures
dues:readRead dues records
dues:writeManage dues records
emails:readRead camp email
emails:writeManage camp email
export:readRead camp data exports
inventory:readRead camp inventory
kitchen:readRead kitchen assignments
logistics:readRead camp logistics
meetings:readRead camp meetings
meetings:writeManage camp meetings
members:readRead member records
members:writeManage member records
onboarding:readRead member onboarding progress
onboarding:writeManage member onboarding progress
org:readRead organization configuration
reports:readRead camp reports
sap:readRead Setup Access Pass allocations and assignments
sap:writeManage Setup Access Pass allocations and assignments
scholarships:readRead scholarship requests
scholarships:writeManage scholarship requests
shifts:readRead shift schedules and signups
shifts:writeManage shift schedules and signups
tasks:readRead camp tasks
tickets:readRead camp tickets
tickets:writeManage camp tickets
vehicle-passes:readRead vehicle passes
vehicle-passes:writeManage vehicle passes
vendors:readRead camp vendors

Principle of Least Privilege

Grant only the scopes your integration actually needs:

  • A public-facing member directory only needs members:read
  • A dues reminder bot needs members:read + dues:read
  • A shift scheduling dashboard needs members:read + shifts:read
  • A full AI agent integration (via MCP) needs read + write scopes for the resources it manages

Scope Enforcement

Scopes are enforced server-side on every request regardless of what the client sends. There is no way to elevate a key's permissions without regenerating it with wider scopes in the admin panel.