Added

API keys now carry access scopes

Each API key now has a set of scopes that say what it can do, for example read:sales, read:lettings or write:notes. Every V2 endpoint lists the scope it needs in the API Reference.

Nothing changes for existing keys. Every key issued before today has every scope, so all your current calls keep working.

When we start checking scopes (we'll announce the date here first), a call made with a key that doesn't have the scope it needs will get 403 Forbidden:

{ "error": "This API key doesn't have the write:notes scope" }

New keys are issued with only the scopes the integration needs. If a key is missing a scope it needs, ask us to add it.

Calling the V1 endpoints with an lp_ key needs the use:v1-legacy scope. Existing keys already have it. V1 GUID keys are not affected.