Public API keys
Exchange a public API key’s client ID and secret at Create token, then send the returned access token in theAuthorization: Bearer ... header.
- Organization-scoped keys can exercise their granted public API permissions across the organization.
- Team-scoped keys have an
allowed_team_idsrestriction. Every team checked by the request must be on that allowlist. Organization-level and user-level checks fail even when the URL names an allowed team. - Permission bundles limit the actions a key can perform. Select the exact bundles granted to your key in the endpoint filter. A full-access key still has only the public API key permissions; it does not become a user token.
User OAuth tokens
A user-delegated OAuth token acts as the user who authorized it. The endpoint must accept user identities, and the user must have the required permissions through their roles and resource access. Accepting OAuth does not make an endpoint available to every signed-in user. Some endpoints, such as status updates, require a user token and are unavailable to public API keys even with full access.Request-specific checks
An endpoint can support several request forms with different requirements. The filter includes an endpoint when at least one form matches your selection; each endpoint page explains its request-specific requirements.- Permissions joined by + are all required. Or separates alternatives.
- Publishing a workflow requires
workflows:deployas well asworkflows:write. Saving a draft only needs the write permission. - Ticket archiving requires
tickets:archive. Hard-delete requirestickets:admin;tickets:writegrants neither. - Ticket and message searches without
team_idsuse an organization-level check. A team-scoped key must supply allowed team IDs. - Creating or listing approval delegations with an API key requires
delegator_user_id. Omitting it selects the current user, and a key has no user identity. - Moving a ticket checks both the source and destination teams. One allowed team is insufficient.
- Group ownership, entity sharing, ticket settings, and other resource rules can further restrict access.

