Which API scopes are available?
Quick answer
There are four scopes: `accounts:read` to read accounts, trades, positions, analytics and reports; `accounts:write` to assign and unassign traders; `credentials:read` to read and rotate account credentials; and `trading:write`, reserved for trading endpoints that are planned. A key carries only the scopes you select.
Detailed answer
Scopes keep each integration limited to what it needs.
accounts:read
- List accounts and read one account.
- Trades, positions, orders, rule flags.
- Analytics, equity series and the full report.
accounts:write
- Assign a trader to an account (
PUT /v1/accounts/{account}/trader). - Unassign a trader (
DELETE /v1/accounts/{account}/trader). - Planned account creation and archiving will use it too.
credentials:read
- Read an account's credentials.
- Rotate its password.
trading:write
- Reserved for planned endpoints to open, modify and close positions.
Choosing scopes
- Reporting or analytics job:
accounts:readonly. - Checkout integration:
accounts:writeandcredentials:read. - Support tool for resets:
credentials:read.
Why credentials are separate
Credential access lets a system log in as a trader, so it is the most sensitive scope. Keeping it separate means a reporting job never needs it.
Checking a key's scopes
The Developer page lists each key with its scopes, and the API offers the list of available scopes, so you can audit what each integration can do.
PropExecutor team · Updated