Scopes
A scope is a name a credential may carry. The kernel checks it, never the caller — every surface (API, CLI, MCP, SDK) reaches the same gate, so a scope withheld is withheld everywhere at once.
Scopes are also the vocabulary an app asks for consent in, which is why this list holds names that no command carries: an app can request a power a role can then refuse.
The floor
Section titled “The floor”These reads answer every authenticated operator, with no scope at all. No role can exclude them.
Decided per request
Section titled “Decided per request”One read name can serve many shapes — an app’s own table, for instance, where each app declares in its manifest what lives in it. For these, the requirement is a function of the read’s own parameters rather than a fixed name, so it is not listed under any single scope above.
read.internal.extension_records
admin.users.write
Section titled “admin.users.write”Commands — admin_user.disable · admin_user.enable · admin_user.invite · iam.api_key.create · iam.api_key.revoke · iam.api_key.rotate · operator.access_key.create · operator.access_key.revoke
Reads — read.internal.admin_users · read.internal.api_keys · read.internal.operator_access_keys
audit.read
Section titled “audit.read”Reads — read.internal.audit · read.internal.promotion_activity
catalog.admin.read
Section titled “catalog.admin.read”Reads — read.internal.brands_admin · read.internal.catalog_labels · read.internal.categories_admin · read.internal.collection_admin · read.internal.collections_admin · read.internal.product · read.internal.product_media · read.internal.product_sku_dimensions · read.internal.product_sku_media · read.internal.product_stores
catalog.category.write
Section titled “catalog.category.write”Commands — catalog.category.create · catalog.category.move · catalog.category.set_custom_fields · catalog.category.update
catalog.product.publish
Section titled “catalog.product.publish”Commands — catalog.product.publish · catalog.product.publish_bulk · catalog.product.unpublish · catalog.product.unpublish_bulk
catalog.product.write
Section titled “catalog.product.write”Commands — catalog.brand.archive · catalog.brand.create · catalog.brand.update · catalog.collection.archive · catalog.collection.create · catalog.collection.pin · catalog.collection.reorder · catalog.collection.unarchive · catalog.collection.unpin · catalog.collection.update · catalog.media.attach · catalog.media.detach · catalog.media.reorder · catalog.media.update · catalog.option.create · catalog.option.delete · catalog.option.update · catalog.option_value.create · catalog.option_value.update · catalog.product.archive · catalog.product.categorize · catalog.product.create · catalog.product.uncategorize · catalog.product.update
catalog.read
Section titled “catalog.read”Carried by no command and gating no read — a consent symbol an app manifest may ask for.
catalog.sku.write
Section titled “catalog.sku.write”Commands — catalog.sku.create · catalog.sku.delete · catalog.sku.update
composition.write
Section titled “composition.write”Commands — composition.move · composition.place · composition.placement.remove · composition.placement.reorder · composition.placement.set · composition.remove · composition.reorder · composition.toggle · composition.update_config
content.read
Section titled “content.read”Reads — read.internal.assets · read.internal.pages
content.write
Section titled “content.write”Commands — content.page.archive · content.page.create · content.page.update
custom_fields.write
Section titled “custom_fields.write”Commands — custom_field.archive · custom_field.define · custom_field.update
customer.admin.write
Section titled “customer.admin.write”Commands — customer.anonymize · customer.set_custom_fields · customer_cluster.archive · customer_cluster.create · customer_cluster.pin · customer_cluster.unarchive · customer_cluster.unpin · customer_cluster.update
Reads — read.internal.cluster_admin · read.internal.clusters_admin · read.internal.customer · read.internal.customers
customer.self.read
Section titled “customer.self.read”Carried by no command and gating no read — a consent symbol an app manifest may ask for.
customer.self.write
Section titled “customer.self.write”Commands — customer.address.create · customer.address.delete · customer.address.update · customer.link_cart · order.request_cancellation
extensions.egress.consent
Section titled “extensions.egress.consent”Commands — extension.connection.set
extensions.read
Section titled “extensions.read”Reads — read.internal.available_extensions · read.internal.extension_composition · read.internal.extension_config · read.internal.extension_health · read.internal.installed_extensions · read.internal.instance_extensions · read.internal.payment_methods_admin
extensions.write
Section titled “extensions.write”Commands — extension.config.set · extension.install · extension.uninstall · notification.channel.register
iam.roles.write
Section titled “iam.roles.write”Commands — admin_user.set_role · role.archive · role.create · role.update
Reads — read.internal.roles
inventory.adjust
Section titled “inventory.adjust”Commands — inventory.adjust · inventory.set_level · warehouse.create · warehouse.update
inventory.reserve
Section titled “inventory.reserve”Commands — inventory.commit · inventory.reclaim_expired · inventory.release · inventory.reserve
logistics.read
Section titled “logistics.read”Reads — read.internal.carriers · read.internal.pickup_location · read.internal.pickup_locations · read.internal.routing_suggestion · read.internal.shipping_methods_admin · read.internal.shipping_rates · read.internal.shipping_simulation · read.internal.shipping_zones · read.internal.stock_addable_skus · read.internal.stock_levels · read.internal.warehouses
media.write
Section titled “media.write”Commands — asset.archive · asset.create · media.request_upload
notification.send
Section titled “notification.send”Commands — notification.send
operator.otp.request
Section titled “operator.otp.request”Commands — operator.request_otp
operator.self.write
Section titled “operator.self.write”Commands — admin_user.set_locale
operator.session.mint
Section titled “operator.session.mint”Commands — operator.mint_oidc_session · operator.verify_otp
order.payment.write
Section titled “order.payment.write”Commands — order.payment.record
order.read
Section titled “order.read”Reads — read.internal.notification (any of order.read · order.write) · read.internal.notifications (any of order.read · order.write) · read.internal.order_admin (any of order.read · order.write) · read.internal.orders_admin (any of order.read · order.write) · read.internal.sales_metrics (any of order.read · order.write) · read.internal.shipment_queue (any of order.read · order.write)
order.write
Section titled “order.write”Commands — notification.resend · order.cancel · order.cancel_request.approve · order.cancel_request.decline · order.comment.add · order.create · order.document.attach · order.hold · order.mark_delivered · order.mark_paid · order.mark_preparing · order.mark_shipped · order.refund · order.release_hold · order.shipment.create · order.shipment.mark_delivered · order.shipment.mark_picked_up · order.shipment.mark_ready_for_pickup · order.shipment.mark_shipped · order.shipment.set_tracking · order.shipment.update_tracking_status
Reads — read.internal.active_carts · read.internal.notification (any of order.read · order.write) · read.internal.notifications (any of order.read · order.write) · read.internal.order · read.internal.order_admin (any of order.read · order.write) · read.internal.orders_admin (any of order.read · order.write) · read.internal.sales_metrics (any of order.read · order.write) · read.internal.shipment_queue (any of order.read · order.write)
orders.read
Section titled “orders.read”Carried by no command and gating no read — a consent symbol an app manifest may ask for.
pii.read
Section titled “pii.read”Carried by no command and gating no read — a consent symbol an app manifest may ask for.
platform.admin_driver.mint
Section titled “platform.admin_driver.mint”Commands — platform.admin_driver.mint
platform.extension.action
Section titled “platform.extension.action”Carried by no command and gating no read — a consent symbol an app manifest may ask for.
platform.extension.write
Section titled “platform.extension.write”Commands — platform.extension.config.set · platform.extension.connection.set · platform.extension.install · platform.extension.uninstall
platform.iam.write
Section titled “platform.iam.write”Commands — platform.credential.issue · platform.credential.revoke
platform.read
Section titled “platform.read”Carried by no command and gating no read — a consent symbol an app manifest may ask for.
platform.tenant.write
Section titled “platform.tenant.write”Commands — platform.admin_host.remove · platform.admin_host.set · platform.tenant.provision
promotion.read
Section titled “promotion.read”Reads — read.internal.promotion_admin · read.internal.promotion_simulate · read.internal.promotion_store · read.internal.promotions_admin
promotion.write
Section titled “promotion.write”Commands — promotion.activate · promotion.archive · promotion.code.add · promotion.code.remove · promotion.create · promotion.pause · promotion.unarchive · promotion.update
public
Section titled “public”Commands — cart.add_line · cart.apply_coupon · cart.choose_gift · cart.create · cart.merge · cart.remove_coupon · cart.remove_line · cart.set_buyer · cart.set_custom_fields · cart.set_delivery · cart.set_payer_tax_id · cart.set_payment_method · cart.set_pickup_location · cart.set_postal_code · cart.set_shipping_method · cart.update_line · checkout.place_order · customer.mint_social_session · customer.request_otp · customer.verify_otp · operator.access_key.redeem · payment.attempt.fail · payment.initiate · payment.intent.set_provider_ref · payment.reconcile
purchase.on_behalf
Section titled “purchase.on_behalf”Commands — cart.assign_customer
search.write
Section titled “search.write”Commands — search.redirect.remove · search.redirect.set · search.synonym.remove · search.synonym.set
shipping.write
Section titled “shipping.write”Commands — pickup_location.create · pickup_location.update · shipping.carrier.create · shipping.carrier.update · shipping.method.create · shipping.method.update · shipping.rate.delete · shipping.rate.set · shipping.rate.set_many · shipping.zone.create · shipping.zone.update
tenant.settings.read
Section titled “tenant.settings.read”Reads — read.internal.custom_field_definitions · read.internal.notification_channels · read.internal.notification_template · read.internal.notification_types · read.internal.platform_info · read.internal.stores
tenant.settings.write
Section titled “tenant.settings.write”Commands — notification.channel.set_enabled · notification.template.reset · notification.template.set · tenant.settings.update
tenant.store.write
Section titled “tenant.store.write”Commands — tenant.store.create · tenant.store.set_custom_fields · tenant.store.update