Scopes
A key carries at least one scope, and each endpoint demands exactly one. Grant a key only what the system holding it actually does.
The four scopes
Named as the API calls them; the portal's own tables use the friendlier names in the second column.
| Scope | In the portal | Grants | Endpoints |
|---|---|---|---|
REGISTRATION | Registration API | Creating catalog items, and replaying a create to update one. | |
UPDATE | Update API | Changing and deleting catalog items you have already sent. | |
INVENTORY | Inventory Checker API | Reading your catalog back — one item, or a page of them — and listing the Localoy bookables an item can be linked to for inventory checks. | |
PAYMENT | Payment API | Reading a payment session, reporting how it ended, and recording a refund. This is the scope your checkout page and your gateway callback use. |
Changing a key's scopes is immediate
Edit a key on the Self-Managed page and the new scopes apply to that integration's very next request. Nothing waits for a token to expire, and the key itself does not change — so you can widen or narrow a running integration without redeploying it.