> ## Documentation Index
> Fetch the complete documentation index at: https://docs.beachdepository.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Permissions

> Scopes on an API key

Each key has permission scopes. A request without the required scope returns `403`.

* `organizations:read`, `organizations:update`
* `members:read`
* `fbo_accounts:read`, `fbo_accounts:create`, `fbo_accounts:update`
* `inventory:read`
* `inbound_shipments:read`, `inbound_shipments:create`, `inbound_shipments:update` — `update` is cancel. There is no shipment update endpoint.
* `outbound_requests:read`, `outbound_requests:create`, `outbound_requests:update`
* `outbound_shipments:read`
* `transfer_batches:read`, `transfer_batches:create`, `transfer_batches:update` — the HTTP path is `/transfers`
* `webhooks:manage`

Holding statements require `organizations:read`.

Keys are created in the dashboard under **Settings > API Keys**. See [Authorization](/getting-started#authorization) for how a request sends the key.
