Skip to main content
Every API key carries a set of scopes — the operations it is permitted to perform. Scopes are assigned when a key is minted and enforced server-side on every request. A request whose key lacks the required scope returns 403 with an error code of insufficient_scope (see Errors). Most read scopes are available on every tier, including Free. A handful of advanced market-intelligence scopes (full regime history, flow forecasts, and live WebSocket deltas) require a higher tier; those are marked in the Tier column below.

Read scopes

Market-intelligence scopes

Write scopes

MCP scopes

These gate Model Context Protocol tool invocation. mcp:deploy:mainnet is the highest-privilege scope.

Admin scopes

Tier names (Free, Analyst, Team, Enterprise) follow the live plan definitions. If you hold an older key issued under a previous tier name, your entitlements are unchanged — what a key can do is governed by its scopes, not its tier label.