Authentication

Permissions & Scopes

One scope per capability, presets, and the legacy aliases.

One scope per capability

Every capability c in Panoptes has a scope cap:c — for example cap:create_sale, cap:manage_inventory_items, cap:view_reports. A key calls a console action when it holds a cap: scope for a capability that action's gate accepts.

ModuleExample capabilities
poscreate_sale, update_order_status, cancel_order, void_line, refund_order, manage_tables
catalogedit_price, edit_recipe, manage_promotion, manage_brands
inventorymanage_inventory_items, enter_count, approve_variance, manage_transfers
productioncreate_batch, close_batch, record_waste
purchasingmanage_suppliers, create_purchase_order, receive_purchase, register_supplier_payment
deliverysettle_delivery_account, manage_delivery_policy
cashenter_reconciliation, manage_vault
accountingview_gl, manage_accounting, manage_periods
reportsview_reports, view_profit, view_hq
auditview_audit, resolve_fraud
hrview_hr, manage_employees, manage_attendance, manage_payroll
adminmanage_users, manage_settings, manage_org

Each endpoint in the API Reference lists the credentials it accepts.

Presets

Presets make a large grant easy to pick. They are expanded at mint time and never stored, so a preset that grows later cannot widen an existing key.

  • preset:full — every capability the owner holds. As powerful as the owner; use sparingly.
  • preset:read_only — the read capabilities.
  • preset:<module> — one per module: preset:pos, preset:inventory, preset:hr, …

Legacy scopes

The original seven scopes stay valid as aliases, each mapping to one capability: read:reports, write:sales, write:inventory, write:suppliers, write:purchases, write:catalog, manage:webhooks.

Refusals

StatusMeaning
401Missing, malformed or revoked credential
403The key's scopes or the owner's role do not permit the action, or the plan does not include the module