Authentication & permissions
Choose what your integration can read and change.
Bound to one organization
Send the token in Authorization: Bearer …. Every request checks token expiry, revocation, current membership, organization status, scopes and the actor’s current permissions. Only the current owner issues tokens. Ownership transfer or demotion invalidates the issuing owner’s keys. A token never moves with a person to a different organization.
Actions that need a person
Admin operations, customer checkout impersonation and personal receiving wallets are outside this organization API. Provider verification and wallet signing still require the authorized person.
Financial capabilities
Financial automation requires separate server enablement; check capabilities in Organization settings → Developers before granting scopes. Creating a token does not enable financial actions. Capabilities reports the currently enabled actions and financialActionsEnabled. Financial read scopes remain available when financial writes are disabled.
Credential access
Mailbox passwords and authenticator secrets are omitted by default. The separate profiles:credentials:read scope is required to receive supported profile credential fields on Profiles endpoints. Password hashes, internal OAuth data and identity-verification storage keys are always omitted. Keep tokens and webhook secrets out of browser code and logs.