Integration

Scopes and least privilege

resource:action matrix, write→read implication, and separate keys per CI use case.

OpenAPI contractIssue an API keyFree Solo account

Full document, no authentication, ready for your client generator.

Scopes

A scope is written resource:action. The key only reaches endpoints whose scope it carries. Out of scope → 403 naming the missing one.

Writing implies reading: scenarios:write also grants scenarios:read. runs:trigger is separate from runs:read: triggering consumes run quota.

ResourceReadWrite
Scenariosscenarios:readscenarios:write
Runsruns:readruns:trigger
Incidentsincidents:readincidents:write
Outgoing webhooksalerting:readalerting:write
Maintenance windowsmaintenance:readmaintenance:write
Availability targetssla:readsla:write
Organisation, usage, status pageorg:readorg:write
Membersmembers:read—

Least privilege

Issue one key per use case. Read-only CI: scenarios:read + runs:read. Pipeline that creates monitors: scenarios:write. Post-deploy smoke job: runs:trigger alone if possible. Webhooks: alerting:write only on the service that owns them.

Revoke as soon as a pipeline or workstation changes. A broad key left in a public fork is an incident, not a backlog note.

Recommended matrix

# usage              scopes
# terraform apply    scenarios:write alerting:write maintenance:write sla:write
# terraform plan     scenarios:read  alerting:read  maintenance:read  sla:read
# smoke post-deploy  runs:trigger runs:read
# dashboard RO       scenarios:read runs:read incidents:read org:read