Approved scopes
Only the canonical names above are accepted. Legacy request names such as
engage:read, plans:delete, and accounts:delete are no longer recognized; existing grants that used them were rewritten to their canonical equivalents.
partners:* is an alias for accounts:*
The account object was briefly called a “partner”, and its scopes were partners:read, partners:write, and partners:archive. Those names still work: each resolves one-to-one to the matching accounts:* scope at issuance and on every request, so a client that asks for partners:read is granted and stored as accounts:read. New integrations should use accounts:*; the partners:* names are not advertised by GET /api/v1/meta or OAuth discovery.
Note the narrowing: in the original legacy vocabulary, accounts:read fanned out to accounts, leads, and relationship maps. It no longer does. accounts:read now means the account family only (accounts and buying groups); request leads:* and relationship_maps:* explicitly. Grants that were already expanded under the old rule keep the extra scopes they were given.
Scope groups
Scopes follow aresource:action pattern:
:read— list and get operations:write— create and update operations:archive— archive and delete operationsengage.queue:send— send messages (separate from Engage configuration)
organizations:read is required to discover which organizations a principal can access. users:read is required to list organization users.
Common combinations
Read-only CRM assistant
CRM sync with writes
Add write scopes only for record types the integration should modify:Engagement automation
MCP tools by scope
The MCP server exposes the same catalog as the REST API. Outbound Engage send and campaign start stay REST-only.Organization context
Scopes control what a token can do. Organization context controls where it applies. Most endpoints and MCP tools require an active organization in addition to the correct scope. Provide it with:- header
X-Organization-Id - MCP tool input
headers.xOrganizationId - MCP tool input
params.organizationId - A saved MCP
setActiveOrganizationchoice afterlistOrganizations
403 forbidden.
Errors
When configuring keys or OAuth apps, the Forecastable developer settings UI shows the same scope descriptions listed in the table above.
Live scope list
GET /api/v1/meta returns the current approved scope list, pagination defaults, and rate-limit configuration. This endpoint does not require authentication.
Related guides
API keys
Issue static tokens with a chosen scope set.
OAuth apps
Let users approve a scoped set of permissions for third-party clients.
Rate limits
Per-token limits, 429 responses, and retry behavior.