API key scopes
Settings > Advanced > API Keys, a page restricted to people allowed to manage API keys. A new key gets the Read calls scope and the Linked to a user mode by default, attached to the person who creates it.Scopes
The form's Scopes block offers nine checkboxes. Write scopes do not include the matching read scope: a key that creates calls and must also read them back checks both.
| Scope | What it allows | Additional condition |
|---|---|---|
| Read calls | List the calls visible to the key and read their details: transcript, summary, participants, tasks. | — |
| Write calls | Create a call from a recording, edit or delete the AI notes of the calls visible to the key. | — |
| Read meeting events | List upcoming meetings and their recording status. | — |
| Write meeting events | Create a meeting, send the assistant to it or remove it. | — |
| Read users | List the company's users and read their profile. | — |
| Write users | Create, edit and deactivate users. | The person checking this box must be allowed to create and edit users themselves. |
| Read teams | List teams and their members. | — |
| Write teams | Create, edit and delete teams and their membership. | The person checking this box must be allowed to create and edit teams themselves. |
| Read company | Read the company's information. | — |
A key can never grant more than what the person editing it holds: the condition only applies when the box is checked, a key that already holds the scope is not blocked during a later edit. The exact routes and fields of each scope are described in the public API reference.
Access rules
The form's Access rules field offers three modes. They delimit the calls the key can list, read or edit; they change nothing about users, teams or meetings, which remain those of the whole company.
| Mode | What the key sees |
|---|---|
| Access to everything | All the company's calls, regardless of teams and access rules. |
| Linked to a user | The calls the chosen user has access to: their own, their teams' and those the access rules open to them. The key's access follows the user's. |
| Custom access | Only the calls opened by the access rules the key is a recipient of. Without a rule, the key sees no call. Saving redirects to the Access rules page. |
The key list shows the mode in the Access rules column: Access to everything, Linked to: <user name> or Custom access. The access rules dedicated to API keys are described in Access rule types.