Skip to main content
This page lists everything you can grant in a scoped API key’s policy. To create a scoped key, see Scope a key to specific resources.

Resources

Resources must be inside the new key’s organization, or its project for a project-scoped key. Kernel checks that every object ID exists when you create the key.

Actions

Browsers

Profiles

Vaults

Proxies

Projects and organizations

Operations that need more than one action

List endpoints return only the objects the key can access, so a key without a matching grant gets an empty list.

Not available to scoped keys

Scoped keys get 403 with insufficient_scope on:
  • API key management, including creating, listing, rotating, and deleting keys.
  • Browser pools.
  • Creating browsers that use saved extensions, telemetry export, or app invocations.
  • Any other endpoint not covered by the actions above.