Skip to main content
Scopes control what an API key or OAuth token can read or write. Forecastable checks scopes on every authenticated Integration API request and MCP tool call. Assign the narrowest scopes required for your integration. Both API keys and OAuth apps are configured with an allowed scope list; requests cannot exceed that list. User-backed OAuth and API-key requests are also limited by the user’s current organization role. A token cannot grant access the user does not have in that organization. Client-credential tokens stay token-scoped only.

Approved scopes

Only the canonical names above are accepted. Legacy request names such as engage:read, plans:delete, and accounts:delete are no longer recognized; existing grants that used them were rewritten to their canonical equivalents.

partners:* is an alias for accounts:*

The account object was briefly called a “partner”, and its scopes were partners:read, partners:write, and partners:archive. Those names still work: each resolves one-to-one to the matching accounts:* scope at issuance and on every request, so a client that asks for partners:read is granted and stored as accounts:read. New integrations should use accounts:*; the partners:* names are not advertised by GET /api/v1/meta or OAuth discovery. Note the narrowing: in the original legacy vocabulary, accounts:read fanned out to accounts, leads, and relationship maps. It no longer does. accounts:read now means the account family only (accounts and buying groups); request leads:* and relationship_maps:* explicitly. Grants that were already expanded under the old rule keep the extra scopes they were given.

Scope groups

Scopes follow a resource:action pattern:
  • :read — list and get operations
  • :write — create and update operations
  • :archive — archive and delete operations
  • engage.queue:send — send messages (separate from Engage configuration)
organizations:read is required to discover which organizations a principal can access. users:read is required to list organization users.

Common combinations

Read-only CRM assistant

CRM sync with writes

Add write scopes only for record types the integration should modify:

Engagement automation

MCP tools by scope

The MCP server exposes the same catalog as the REST API. Outbound Engage send and campaign start stay REST-only.

Organization context

Scopes control what a token can do. Organization context controls where it applies. Most endpoints and MCP tools require an active organization in addition to the correct scope. Provide it with:
  • header X-Organization-Id
  • MCP tool input headers.xOrganizationId
  • MCP tool input params.organizationId
  • A saved MCP setActiveOrganization choice after listOrganizations
MCP automatically defaults to the sole accessible organization. Saved choices apply to the same user and token across reconnects and new chats. For user-backed tokens, Forecastable also checks the user’s role in that organization. Selecting an organization the user cannot read fails with 403 forbidden.

Errors

When configuring keys or OAuth apps, the Forecastable developer settings UI shows the same scope descriptions listed in the table above.

Live scope list

GET /api/v1/meta returns the current approved scope list, pagination defaults, and rate-limit configuration. This endpoint does not require authentication.

API keys

Issue static tokens with a chosen scope set.

OAuth apps

Let users approve a scoped set of permissions for third-party clients.

Rate limits

Per-token limits, 429 responses, and retry behavior.