Scopes
A scoped key can do only what its scopes allow. A :write scope includes the :read scope of the same area. Full-access keys have every scope. The scope each endpoint needs is shown on its reference entry.
| Scope | Area | Allows |
|---|---|---|
account:read | Account | Profile, plan, site slots, limits and usage, frozen state and why. |
account:write | Account | Refresh usage measurements. |
billing:read | Billing | Subscription status, payment due, invoices and invoice PDFs, add-ons. |
sites:read | Sites | List and read sites: status, nameservers, CDN, indexation, SEO, platform, usage, health. |
sites:write | Sites | Create sites, change settings and PHP version, purge cache, reinstall, recheck health, run Site Cleaner. |
sites:delete | Sites | Delete sites (kept separate on purpose). |
sites:login | Sites | One-click admin login links (WordPress, Joomla, Drupal and the other applications). |
dns:read | DNS | Read DNS records and nameserver status. |
dns:write | DNS | Add, change and delete DNS records. |
backups:read | Backups | List backups and get download links. |
backups:write | Backups | Create backups, restore a backup, delete a backup. |
files:read | Files | List folders and read files of a site. |
files:write | Files | Upload, create folders, rename and delete files of a site. |
logs:read | Logs | Error log and access log of a site. |
tickets:read | Support | Read your support tickets. |
tickets:write | Support | Open tickets and reply to them. |
content:read | Content | Read posts, pages and the auto-posting campaigns of the account. |
content:write | Content | Publish and change posts and pages on any site type, upload pictures, and start or pause auto-posting campaigns. |
kb:read | Knowledge base | Search the knowledge base (needs no scope; listed for completeness). |
registrars:read | Registrar connections | Read your connected registrar accounts (never their keys), which domains get their nameservers set automatically, and the nameserver update history. |
registrars:write | Registrar connections | Connect and disconnect registrar accounts, test and refresh them, switch automatic nameserver updates on or off, and update nameservers now. |
security:read | Site security | Read "I'm Under Attack", the firewall rules and the bot protection of your Cloudflare sites. |
security:write | Site security | Switch "I'm Under Attack" on and off, add, change and remove firewall rules, and change bot protection. |
wayback:read | Wayback restore | Read your archive restores, restore credits and prices, and look a domain up in the web archive. |
wayback:write | Wayback restore | Start a restore and order it with a restore credit. |
extdeploy:read | External Deploy | Read your sites on third-party hosts, their deploy logs and domains, and your connected hosting accounts (never their credentials). |
extdeploy:write | External Deploy | Remove external sites, attach and detach their domains, and test or disconnect hosting accounts. |
mail:read | Read the mailboxes, aliases, forwarders and out-of-office replies of your sites (never a password). | |
mail:write | Set mail up, create and delete mailboxes, set new mailbox passwords, and change aliases, forwarders, the catch-all and out-of-office replies. | |
rank:read | Rank tracking | Read your tracked domains, keywords, Google positions and their history, and the rank tracking plans. |
rank:write | Rank tracking | Add and remove tracked domains, Google versions and keywords, and run "Check now". |
aivis:read | AI visibility | Read your tracked brands and prompts, what each AI assistant answered, who is cited instead, and the AI visibility plans. |
aivis:write | AI visibility | Add and remove tracked brands and prompts, choose the assistants and market, and run "Check now". |
index:read | Index checker | Read the pages you track in the index checker and their history. |
index:write | Index checker | Add and remove tracked pages, change how often they are checked, and run "Check now". |
redis:read | Redis | See whether Redis is on for the account and for each site. |
redis:write | Redis | Switch Redis on or off for a site (buying Redis stays on the Redis page). |
moneysites:read | Money sites | Read the money-site catalogue, your money sites, their state and usage, and your money-site orders. |
moneysites:write | Money sites | Order a money-site plan, and add or remove the free WooCommerce install on a PBN-line WordPress site. |
seo:read | SEO tools | Read the SEO tools catalogue, your SEO tools subscription, and price a selection (bundle and yearly discounts included). |
research:read | Keyword research + domain overview | Read your research usage, the countries covered and your saved keyword lists. |
research:run | Keyword research + domain overview | Run keyword research and domain reports (uses credits of your plan). |
vetting:read | Domain vetting | Read your vetting reports, credits and saved domain alerts. |
vetting:write | Domain vetting | Run a vetting report (spends one credit) and manage your saved domain alerts. |
footprint:read | Footprint checker | Read your footprint scores, reports and findings. |
footprint:write | Footprint checker | Start a check, and add or remove sites hosted elsewhere. |
audit:read | Site audit | Read your audits and their findings. |
audit:write | Site audit | Start an audit and verify that a site is yours. |
backlinks:read | Backlink monitor | Read the links and backlink profiles you watch, and their history. |
backlinks:write | Backlink monitor | Add and remove watched links and domains, change how often they are checked, and run "Check now" / "Refresh now". |
mentions:read | Brand mentions | Read the brands you listen for and the mentions we have found. |
mentions:write | Brand mentions | Add and remove brands, change how often they are checked, and run "Check now". |
local:read | Local rankings | Read your tracked businesses, their map and local positions and their business-profile facts. |
local:write | Local rankings | Add businesses, towns and keywords, and ask for a check. |
reports:read | Client reports | Read your clients and the reports made for them. |
reports:write | Client reports | Make a report, send it, and turn a share link off. |
updates:read | Plugin updates | Read the plugin updates we held back because they stopped a site working. |
updates:write | Plugin updates | Ask us to try a held plugin update again. |
extradb:read | Extra databases | Read the extra databases of your sites, their paid period, size, restore points and the price. |
extradb:write | Extra databases | Remove an extra database, restore one from its own daily backup, cancel or keep one at the end of its paid months, and add one where your account gets them free. |
staging:read | Staging | Read your staging add-on (plan, slots, price) and your staging sites with the progress of their copies. |
staging:write | Staging | Create staging sites, copy staging to live and live to staging, switch on SFTP or reset its password, see the share password, remove staging sites and cancel the add-on. |
turnstile:read | Turnstile | Read whether the Turnstile bot check is on for a site, and how it is set up. |
turnstile:write | Turnstile | Switch the Turnstile bot check on or off for a site, change which forms it protects, and replace its secret key. |
cron:read | Cron jobs | See a site's cron jobs (scheduled tasks), their schedules, commands and the output of their last runs. |
cron:write | Cron jobs | Add, change, switch on or off, run now and delete a site's cron jobs. A cron job runs commands on the site. |
reputation:read | Reputation monitoring | Read your watched businesses, their review profiles, ratings, reviews and brand page one. |
reputation:write | Reputation monitoring | Add and remove businesses, confirm review profiles, brand terms and ask for a fresh reading. |
products:read | Product price tracking | Read your tracked products and how they sit on Google Shopping and Amazon. |
products:write | Product price tracking | Add and remove tracked products. |
competitors:read | Competitor tracking | Read your watched competitor domains and their weekly readings. |
competitors:write | Competitor tracking | Add and remove watched competitor domains. |
agency:read | Agency SEO data | Read your tracked domains and their weekly authority and link readings. |
agency:write | Agency SEO data | Add, label, switch off and remove tracked domains. |
boost:read | Performance Boost | See whether Performance Boost is on for the account, its level and the price of each level. |
prodisc:read | Pro plugin discount | See whether the account gets 50% off our Pro plugins and which plugins are in the offer. |
A call without the scope gets 403 scope_missing, with details.required naming the scope it needs. Jobs (GET /jobs) need account:read; the knowledge base and GET /limits work with any key.