templates:read | Read templates: the list, one template’s documents, roles, subjects, questions and fields, and the geometry of every field on it. |
templates:write | Author a template from an uploaded PDF. Field extraction runs on it, and what it produces is what every envelope made from it will ask for. |
envelopes:read | Read one envelope: its status, its recipients and their delivery state. |
envelopes:write | Create envelopes from a template, singly or in a batch, send them, and mint embedded signing URLs for their recipients. ⚠️ This is the scope that emails real people and spends billing allowance on a live key. |
documents:read | Read a document’s bytes: the pages of a document belonging to a template this key can already see, as PDF; and, separately, the executed contract of any envelope this key’s organisation owns — original or sealed — via GET .../envelopes/{envelopeId}/documents. ⚠️ NARROWER THAN envelopes:read on purpose: a key that may read an envelope’s status is not thereby a key that may fetch what it holds. |
webhooks:read | Read the registered webhook endpoints. Never their signing secrets. |
webhooks:write | Register, change, rotate the secret of and delete webhook endpoints. ⚠️ An endpoint is where envelope events — carrying recipient names and addresses — are POSTed, so this scope decides where a copy of them goes. |