Ability to assign granular access controls to API keys.

πŸ” Problem Statement

All Pelcro API keys have full access to every resource and action. There is no way to restrict an API key to specific endpoints or operations, which creates unnecessary security exposure β€” especially when sharing keys with third-party integrators or internal tools with limited scope.


πŸ’‘ User Story

As a Pelcro admin, I want to assign granular access controls (scopes) to individual API keys, so that each key is limited to only the resources and actions it needs β€” reducing security risk.


🎯 Definition of Done (DoD)

A feature is done when:

βœ”οΈ Given API key creation or editing, when an admin selects specific permission scopes (e.g. read-only subscriptions, write invoices), then the key is restricted to those scopes β€” and any request outside the allowed scopes returns a 403 Forbidden error.

Please authenticate to join the conversation.

Upvoters
Status

Backlog

Board
πŸ’‘

Pelcro Product

Date

7 months ago

Author

Sara Habib

Subscribe to post

Get notified by email when there are changes.