π Problem Statement
All Pelcro API keys have full access to every resource and action. There is no way to restrict an API key to specific endpoints or operations, which creates unnecessary security exposure β especially when sharing keys with third-party integrators or internal tools with limited scope.
π‘ User Story
As a Pelcro admin, I want to assign granular access controls (scopes) to individual API keys, so that each key is limited to only the resources and actions it needs β reducing security risk.
π― Definition of Done (DoD)
A feature is done when:
βοΈ Given API key creation or editing, when an admin selects specific permission scopes (e.g. read-only subscriptions, write invoices), then the key is restricted to those scopes β and any request outside the allowed scopes returns a 403 Forbidden error.
Please authenticate to join the conversation.
Backlog
Pelcro Product
7 months ago

Sara Habib
Get notified by email when there are changes.
Backlog
Pelcro Product
7 months ago

Sara Habib
Get notified by email when there are changes.