Skip to main content
HomeReferenceAPI key scopes

API key scopes

On this page

A scope limits what an API key can do. A scoped key never exceeds the permissions of the user who created it: Coder checks the scope and the user's roles on every request, so a scope narrows access and never widens it.

Pass --scope once per scope when you create a token:

coder tokens create --scope coder:workspaces.access --scope template:read

A token created without an explicit scope uses coder:all, which grants the full permissions of its owner. To create and revoke tokens, refer to Sessions & API Tokens.

This page lists every canonical scope a token can request and the deprecated names Coder accepts for backward compatibility. Coder rejects any scope name not listed on this page with a 400 response.

Built-in scopes

Built-in scopes cover the two broadest cases: the full permissions of the owner, and connections to workspace applications.

ScopeGrants
coder:allAll operations.
coder:application_connectAbility to connect to applications.

Composite scopes

A composite scope groups the permissions that one task needs, so you can scope a token to that task without listing each permission. Each scope below grants the permissions in its table.

coder:apikeys.manage_self

ResourceActions
api_keycreate, delete, read, update

coder:templates.author

ResourceActions
filecreate, read
templatecreate, delete, read, update, view_insights

coder:templates.build

ResourceActions
filecreate, read
provisioner_jobsread
templateread

coder:workspaces.access

ResourceActions
organization_memberread
templateread
workspaceapplication_connect, read, ssh

coder:workspaces.create

ResourceActions
organization_memberread
templateread, use
workspacecreate, read, start, stop, update

coder:workspaces.delete

ResourceActions
organization_memberread
templateread, use
workspacedelete, read

coder:workspaces.operate

ResourceActions
organization_memberread
templateread
workspaceread, start, stop, update

Low-level scopes

A low-level scope grants one action on one resource, written as resource:action. Combine low-level scopes when no composite scope matches the task.

The resource:* form grants every action on that resource, including actions not listed on this page.

api_key

ScopeDescription
api_key:*Every action on api_key, including actions not listed on this page.
api_key:createCreate an API key.
api_key:deleteDelete an API key.
api_key:readRead API key details (secrets are not stored).
api_key:updateUpdate an API key, for example its expiry.

chat_model_config

ScopeDescription
chat_model_config:readRead chat model configs.
chat_model_config:shareShare a chat model config with other users or groups.

file

ScopeDescription
file:*Every action on file, including actions not listed on this page.
file:createCreate a file.
file:readRead files.

organization

ScopeDescription
organization:*Every action on organization, including actions not listed on this page.
organization:deleteDelete an organization.
organization:readRead organizations.
organization:updateUpdate an organization.

template

ScopeDescription
template:*Every action on template, including actions not listed on this page.
template:createCreate a template.
template:deleteDelete a template.
template:readRead template.
template:updateUpdate a template.
template:useUse the template to initially create a workspace, then workspace lifecycle permissions take over.

user

ScopeDescription
user:*Every action on user, including actions not listed on this page.
user:readRead user data.
user:read_personalRead personal user data like user settings and auth links.
user:update_personalUpdate personal data.

user_secret

ScopeDescription
user_secret:*Every action on user_secret, including actions not listed on this page.
user_secret:createCreate a user secret.
user_secret:deleteDelete a user secret.
user_secret:readRead user secret metadata and value.
user_secret:updateUpdate user secret metadata and value.

user_skill

ScopeDescription
user_skill:*Every action on user_skill, including actions not listed on this page.
user_skill:createCreate a user skill.
user_skill:deleteDelete a user skill.
user_skill:readRead user skill metadata and content.
user_skill:updateUpdate user skill metadata and content.

workspace

ScopeDescription
workspace:*Every action on workspace, including actions not listed on this page.
workspace:application_connectConnect to workspace apps via browser.
workspace:createCreate a new workspace.
workspace:deleteDelete workspace.
workspace:readRead workspace data to view on the UI.
workspace:sshSSH into a given workspace.
workspace:startStart a workspace.
workspace:stopStop a workspace.
workspace:updateEdit workspace settings (scheduling, permissions, parameters).

Deprecated scope names

Coder still accepts the following names and stores each one as its canonical equivalent. Use the canonical name.

Deprecated nameCanonical name
allcoder:all
application_connectcoder:application_connect