Skip to content
v0.3

Scopes

A scope is a name a credential may carry. The kernel checks it, never the caller — every surface (API, CLI, MCP, SDK) reaches the same gate, so a scope withheld is withheld everywhere at once.

Scopes are also the vocabulary an app asks for consent in, which is why this list holds names that no command carries: an app can request a power a role can then refuse.

These reads answer every authenticated operator, with no scope at all. No role can exclude them.

read.internal.whoami

One read name can serve many shapes — an app’s own table, for instance, where each app declares in its manifest what lives in it. For these, the requirement is a function of the read’s own parameters rather than a fixed name, so it is not listed under any single scope above.

read.internal.extension_records

Commandsadmin_user.disable · admin_user.enable · admin_user.invite · iam.api_key.create · iam.api_key.revoke · iam.api_key.rotate · operator.access_key.create · operator.access_key.revoke

Readsread.internal.admin_users · read.internal.api_keys · read.internal.operator_access_keys

Readsread.internal.audit · read.internal.promotion_activity

Readsread.internal.brands_admin · read.internal.catalog_labels · read.internal.categories_admin · read.internal.collection_admin · read.internal.collections_admin · read.internal.product · read.internal.product_media · read.internal.product_sku_dimensions · read.internal.product_sku_media · read.internal.product_stores

Commandscatalog.category.create · catalog.category.move · catalog.category.set_custom_fields · catalog.category.update

Commandscatalog.product.publish · catalog.product.publish_bulk · catalog.product.unpublish · catalog.product.unpublish_bulk

Commandscatalog.brand.archive · catalog.brand.create · catalog.brand.update · catalog.collection.archive · catalog.collection.create · catalog.collection.pin · catalog.collection.reorder · catalog.collection.unarchive · catalog.collection.unpin · catalog.collection.update · catalog.media.attach · catalog.media.detach · catalog.media.reorder · catalog.media.update · catalog.option.create · catalog.option.delete · catalog.option.update · catalog.option_value.create · catalog.option_value.update · catalog.product.archive · catalog.product.categorize · catalog.product.create · catalog.product.uncategorize · catalog.product.update

Carried by no command and gating no read — a consent symbol an app manifest may ask for.

Commandscatalog.sku.create · catalog.sku.delete · catalog.sku.update

Commandscomposition.move · composition.place · composition.placement.remove · composition.placement.reorder · composition.placement.set · composition.remove · composition.reorder · composition.toggle · composition.update_config

Readsread.internal.assets · read.internal.pages

Commandscontent.page.archive · content.page.create · content.page.update

Commandscustom_field.archive · custom_field.define · custom_field.update

Commandscustomer.anonymize · customer.set_custom_fields · customer_cluster.archive · customer_cluster.create · customer_cluster.pin · customer_cluster.unarchive · customer_cluster.unpin · customer_cluster.update

Readsread.internal.cluster_admin · read.internal.clusters_admin · read.internal.customer · read.internal.customers

Carried by no command and gating no read — a consent symbol an app manifest may ask for.

Commandscustomer.address.create · customer.address.delete · customer.address.update · customer.link_cart · order.request_cancellation

Commandsextension.connection.set

Readsread.internal.available_extensions · read.internal.extension_composition · read.internal.extension_config · read.internal.extension_health · read.internal.installed_extensions · read.internal.instance_extensions · read.internal.payment_methods_admin

Commandsextension.config.set · extension.install · extension.uninstall · notification.channel.register

Commandsadmin_user.set_role · role.archive · role.create · role.update

Readsread.internal.roles

Commandsinventory.adjust · inventory.set_level · warehouse.create · warehouse.update

Commandsinventory.commit · inventory.reclaim_expired · inventory.release · inventory.reserve

Readsread.internal.carriers · read.internal.pickup_location · read.internal.pickup_locations · read.internal.routing_suggestion · read.internal.shipping_methods_admin · read.internal.shipping_rates · read.internal.shipping_simulation · read.internal.shipping_zones · read.internal.stock_addable_skus · read.internal.stock_levels · read.internal.warehouses

Commandsasset.archive · asset.create · media.request_upload

Commandsnotification.send

Commandsoperator.request_otp

Commandsadmin_user.set_locale

Commandsoperator.mint_oidc_session · operator.verify_otp

Commandsorder.payment.record

Readsread.internal.notification (any of order.read · order.write) · read.internal.notifications (any of order.read · order.write) · read.internal.order_admin (any of order.read · order.write) · read.internal.orders_admin (any of order.read · order.write) · read.internal.sales_metrics (any of order.read · order.write) · read.internal.shipment_queue (any of order.read · order.write)

Commandsnotification.resend · order.cancel · order.cancel_request.approve · order.cancel_request.decline · order.comment.add · order.create · order.document.attach · order.hold · order.mark_delivered · order.mark_paid · order.mark_preparing · order.mark_shipped · order.refund · order.release_hold · order.shipment.create · order.shipment.mark_delivered · order.shipment.mark_picked_up · order.shipment.mark_ready_for_pickup · order.shipment.mark_shipped · order.shipment.set_tracking · order.shipment.update_tracking_status

Readsread.internal.active_carts · read.internal.notification (any of order.read · order.write) · read.internal.notifications (any of order.read · order.write) · read.internal.order · read.internal.order_admin (any of order.read · order.write) · read.internal.orders_admin (any of order.read · order.write) · read.internal.sales_metrics (any of order.read · order.write) · read.internal.shipment_queue (any of order.read · order.write)

Carried by no command and gating no read — a consent symbol an app manifest may ask for.

Carried by no command and gating no read — a consent symbol an app manifest may ask for.

Commandsplatform.admin_driver.mint

Carried by no command and gating no read — a consent symbol an app manifest may ask for.

Commandsplatform.extension.config.set · platform.extension.connection.set · platform.extension.install · platform.extension.uninstall

Commandsplatform.credential.issue · platform.credential.revoke

Carried by no command and gating no read — a consent symbol an app manifest may ask for.

Commandsplatform.admin_host.remove · platform.admin_host.set · platform.tenant.provision

Readsread.internal.promotion_admin · read.internal.promotion_simulate · read.internal.promotion_store · read.internal.promotions_admin

Commandspromotion.activate · promotion.archive · promotion.code.add · promotion.code.remove · promotion.create · promotion.pause · promotion.unarchive · promotion.update

Commandscart.add_line · cart.apply_coupon · cart.choose_gift · cart.create · cart.merge · cart.remove_coupon · cart.remove_line · cart.set_buyer · cart.set_custom_fields · cart.set_delivery · cart.set_payer_tax_id · cart.set_payment_method · cart.set_pickup_location · cart.set_postal_code · cart.set_shipping_method · cart.update_line · checkout.place_order · customer.mint_social_session · customer.request_otp · customer.verify_otp · operator.access_key.redeem · payment.attempt.fail · payment.initiate · payment.intent.set_provider_ref · payment.reconcile

Commandscart.assign_customer

Commandssearch.redirect.remove · search.redirect.set · search.synonym.remove · search.synonym.set

Commandspickup_location.create · pickup_location.update · shipping.carrier.create · shipping.carrier.update · shipping.method.create · shipping.method.update · shipping.rate.delete · shipping.rate.set · shipping.rate.set_many · shipping.zone.create · shipping.zone.update

Readsread.internal.custom_field_definitions · read.internal.notification_channels · read.internal.notification_template · read.internal.notification_types · read.internal.platform_info · read.internal.stores

Commandsnotification.channel.set_enabled · notification.template.reset · notification.template.set · tenant.settings.update

Commandstenant.store.create · tenant.store.set_custom_fields · tenant.store.update