Concepts
Scopes
Scopes decide what a key can do. Pick them when you create the key; give each key only what it needs.
A request to an endpoint whose scope is missing from the key fails with 403 INSUFFICIENT_SCOPE. Scopes cannot be added to an existing key: create a new key and revoke the old one.
Not available: payments, wallet, tokens, transfers and account settings. No scope gives access to them.
All scopes#
| Scope | Allows |
|---|---|
profile:read | Read your profile and public profiles of other users. |
posts:read | Read posts (yours and those you can see in the app) and their comments. |
posts:write | Upload media, publish, edit and delete your posts. |
comments:write | Write comments and delete your comments (or comments on your posts). |
likes:write | Like and unlike posts. |
follows:write | Follow and unfollow users. |
stories:write | Publish stories. |
store:read | Read your Bloop store and its products. |
store:write | Edit your store, create, update and delete products, update stock. |
orders:read | Read the orders received by your store. |
orders:write | Mark orders as shipped. |
chat:read | Read your conversations and their messages. |
chat:write | Send messages (with the anti-spam rule). |
Endpoints by scope#
All paths are relative to https://api.linework.app/open/v1.
| Endpoint | Scope |
|---|---|
GET /me | profile:read |
GET /users/{id} | profile:read |
GET /users/by-username/{username} | profile:read |
GET /me/posts | posts:read |
GET /users/{id}/posts | posts:read |
GET /posts/{id} | posts:read |
GET /posts/{id}/comments | posts:read |
POST /media | posts:write, stories:write or store:write |
POST /posts | posts:write |
PATCH /posts/{id} | posts:write |
DELETE /posts/{id} | posts:write |
POST /posts/{id}/comments | comments:write |
DELETE /comments/{id} | comments:write |
POST DELETE /posts/{id}/like | likes:write |
POST DELETE /users/{id}/follow | follows:write |
POST /stories | stories:write |
GET /store | store:read |
POST PATCH /store | store:write |
GET /store/products | store:read |
POST /store/products | store:write |
PATCH DELETE /store/products/{id} | store:write |
PATCH /store/products/{id}/stock | store:write |
GET /store/orders | orders:read |
GET /store/orders/{id} | orders:read |
POST /store/orders/{id}/ship | orders:write |
GET /conversations | chat:read |
GET /conversations/{id}/messages | chat:read |
POST /conversations/{id}/messages | chat:write |
POST /messages | chat:write |
The API Reference is the source of truth: every operation lists its required scope.
Suggested sets#
| Integration | Scopes |
|---|---|
| Publishing bot | profile:read posts:read posts:write stories:write |
| Community manager | posts:read comments:write likes:write |
| Store sync | store:read store:write orders:read orders:write |
| Support chat bot | chat:read chat:write (+ orders:read to look up orders) |