The five scopes
All three default scopes are read-only. Write access must be ticked by hand, and the interface warns you when you do.
Endpoints covered by each scope
account:read
account:read
logs:read
logs:read
usage:read
usage:read
keys:read
keys:read
keys:write
keys:write
Refusal responses
There are two kinds of refusal, and the difference is whether ticking another scope fixes it.Missing scope
The endpoint is available to Admin Keys, but this key does not have the required scope. Edit the key and tick it.message names the scope that is missing.