Permissions
Give people and backend services only the provider, merchant, environment, and operation access they require.
On this page
Human roles and service keys
A team role authorizes a signed-in person. A Carden API key authorizes one backend service for one merchant, provider integration, and environment. Review both when responsibilities change.
API key scopes
| Scope | Use |
|---|---|
| invoices:read | Read a QuickBooks source explicitly linked to the payment integration. |
| enrichment:write | Prepare Stripe or Square context from an inline or linked invoice. |
| payments:write | Submit immutable provider payment reports. |
| integrations:read | Read supported integration and QuickBooks sync state. |
| integrations:write | Create QuickBooks invitations or queue supported sync work. |
Use payment-integration keys for payment preparation and reports. Use QuickBooks-integration keys for connection management. A report-only worker usually needs only payments:write.
Assign roles by responsibility
- Keep ownership and membership management with a small group.
- Give integration maintainers only needed provider setup and troubleshooting permissions.
- Give finance reviewers reporting access without unnecessary key management.
- Use read-only access when no configuration change is needed.
Handle denied operations
- Confirm merchant, integration, and environment.
- For a browser action, inspect membership and role.
- For an API request, inspect key provider, status, and scopes.
- Grant the smallest additional permission or deploy a replacement key.
- Retest and retain the safe request ID if access remains denied.
A 401 or 403 requires credential or permission repair. Repeated delivery with the same unauthorized key continues to fail.