Skip to content
Dashboard

Authentication

All requests to the SuiteOp API authenticate with a Bearer token in the Authorization header. There are two kinds of token:

  • API keys (sk_live_…) — long-lived machine credentials that act as a member of your organization. This page covers these.
  • OAuth 2.1 access tokens — tokens an app or AI assistant obtains after a person authorizes it. Use these when an application acts on a specific user’s behalf. See OAuth 2.1 user-delegated access.

Both are presented the same way — as a Bearer token — and both work on the REST API and the MCP server. A token that starts with sk_ is treated as an API key; anything else is treated as an OAuth access token.

Authorization: Bearer sk_live_your_key_here

The Bearer scheme is case-insensitive.

PartExampleMeaning
Prefixsk_Always present on API keys
Environmentlive_The SuiteOp environment that issued the key
Secretabc123…48 random URL-safe base64 characters (A–Z a–z 0–9 - _)
  • sk_live_ keys are issued by, and the only keys accepted by, the production API. Every key you create in the SuiteOp dashboard is an sk_live_ key and reaches your organization’s real data. Keep it out of source control and client-side code.
  • sk_test_ keys exist only on SuiteOp’s internal non-production servers. There is no customer sandbox, and the production base URLs reject an sk_test_ key with 401: This server only accepts sk_live_ API keys — check your organization’s regional base URL and environment.

Each key is issued with a set of permissions, and the permission names are the scopes. They are the same permissions an organization role grants in the dashboard, written in snake_case: reading tasks needs view_tasks, not tasks:read.

  • A key must carry at least one permission.
  • You can only give a key permissions you hold yourself.
  • Permissions are fixed once the key exists. You can rename a key, but to change its permissions you revoke it and create a new one.
  • A request for an operation whose permission the key lacks returns 403 authorization_error with the code FORBIDDEN and a message naming the missing permission, for example Missing permission: view_tasks.
  • An operation can require more than one permission. createUpsell, for example, needs both modify_guides and modify_properties. Some filters also need an extra permission. The includeCancelled, includeTriage and includeDeleted filters on listTasks also require modify_tasks.
  • An API key sees every property in the organization. An OAuth token is limited to the properties the authorizing user can reach.

OAuth clients request these same permission names as OAuth scopes, plus the standard openid, profile, email and offline_access. See OAuth 2.1.

All 55 permissions, grouped as the dashboard’s permission editor groups them. The right-hand column lists the public operations (by operation ID, as shown in the API Reference) that each permission unlocks. Permissions marked none gate no public operation today. They are accepted when you create a key but only matter inside the SuiteOp apps.

AreaPermissionPublic operations it unlocks
Dashboardview_dashboardsearch
Tasksview_taskslistDepartments, listTasks, getTask, listTaskRequirements, listAnswerLists
Tasksmodify_taskscreateDepartment, updateDepartment, createTask, updateTask, updateTaskStatus, applyTemplateToTask, addTaskRequirement, updateTaskRequirement, createTranslation, createAnswerList, updateAnswerList, archiveAnswerList, restoreAnswerList, duplicateAnswerList, addAnswerListChoice, updateAnswerListChoice, removeAnswerListChoice, reorderAnswerListChoices, setAnswerListScoring
Tasksdelete_tasksdeleteTask
Task templatesview_task_templateslistTemplates, getTemplate
Task templatesmanage_task_templatescreateTemplate, updateTemplate, addTemplateGroup, updateTemplateGroup, addTemplateChecklistItem, updateTemplateChecklistItem
Task templatesdelete_task_templatesnone
Task templatesmanage_task_ratesnone
Devicesview_deviceslistDevices, getDevice
Devicescontrol_devicelockDevice, unlockDevice, setDeviceTemperature, setDeviceMode, refreshDeviceStatus
Devicesmodify_devicesassignDeviceToProperty
Propertiesview_propertieslistProperties, getProperty, listPropertyGroups, getPropertyGroup, listElementCategories, listElementCatalog, listPropertyElements, listInstructions, getInstruction, listPortalBrandings, listPrecheckSteps, getPrecheckStep, listPortals, getPortal, listUpsells, getUpsell, listUpsellsByProperty, listUpsellVisibilityRules, listEntityScopes, listTags, listPropertyTags
Propertiesmodify_propertiesupdateProperty, updatePropertyStatus, createPropertyGroup, updatePropertyGroup, createElementCatalogEntry, updateElementCatalogEntry, createPropertyElement, updatePropertyElement, createInstruction, updateInstruction, deleteInstruction, reorderInstruction, createPortalBranding, updatePortalBranding, createPrecheckStep, updatePrecheckStep, createPortal, updatePortal, assignPortalToProperty, createUpsell, updateUpsell, reorderUpsell, updateEntityScopes, addEntityScopes, removeEntityScopes, deleteElementCatalogEntry, deletePropertyElement
Propertiesdelete_propertiesnone
Reservationsview_reservationslistReservations, getReservation, getReview
Reservationsmodify_reservationscreateReservation, updateReservation, updateCheckInState
Guest IDsview_guest_idsnone
Portalsview_guideslistPortalManuals, listPortalManualsByProperty, listPortalManualCategories
Portalsmodify_guidescreatePortalManual, updatePortalManual, createPortalManualCategory, updatePortalManualCategory, reorderPortalManualCategories, deletePortalManualCategory, createUpsell, retranslateGuideText
Portalsdelete_guidenone
Integrationsview_integrationnone
Integrationsmanage_integrationsnone
Organizationview_organizationgetOrganization
Organizationmanage_organizationlistEmailTemplates, getEmailTemplate, create_email_template, modify_email_template, updateEmailTemplate, initializeLanguageTranslations, getLanguageCoverage
Organizationmanage_billingnone
Usersview_userslistTeamMembers, getMember
Usersmanage_usersinviteMember, updateMember, updateMemberRole, suspendMember, addPropertyScope, removePropertyScope, updateMemberScopes
Usersdelete_usersnone
Access codesprivate_codenone
Access codesview_lock_codelistCodes, getCode
Access codesmanage_lock_codecreateCode, updateCode, deleteCode
Access codesview_staff_codesnone
Eventsview_eventnone
Eventsmanage_eventnone
Analyticsview_analyticsnone
Analyticsview_logsnone
Workflowsview_workflowslistWorkflowZapierSteps
Workflowsmanage_workflowscreate_workflow, modify_workflow, update_workflow, set_workflow_scopes, publish_workflow
Workflowsdelete_workflowsnone
Paymentsview_paymentslistPaymentAccounts
Paymentsmanage_paymentsnone
Payoutsview_payoutsnone
Payoutsmanage_payoutsnone
Inboxview_inboxnone
Inboxmanage_inboxnone
Inboxmanage_inbox_assigneesnone
Inboxmanage_message_templatesnone
Booking engineview_booking_enginenone
Booking enginemanage_booking_enginenone
Shiftsview_shiftslistShifts, getShift, listTimeEntries, listClockedShifts
Shiftsmanage_shiftsnone
Shiftsapprove_time_entrieslistCostsByPeriod, getCostsForDay
Shiftsview_team_locationsnone
Accountaccount_adminnone
Not in editormanage_connectionsnone

The dashboard’s permission editor does not list manage_connections yet, and no public operation needs it or either payouts permission.

Seven operations need no specific permission. searchCoverIcons and searchStockPhotos are open to any valid key. getTranslationEntries and getTranslationEntriesBatch need the key to hold at least one permission of any kind. The three webhook subscription operations act only on the calling credential’s own subscriptions: listWebhookSubscriptions and deleteWebhookSubscription are open to any valid credential, and createWebhookSubscription needs at least one permission plus the permission of the event you subscribe to. Each translation’s text is then gated by the domain it belongs to: see Translations.

Pick the smallest set that covers the operations your integration calls.

ActionHow
CreateSettings → Developer → Create API Key
ViewShown once at creation; not retrievable afterwards
RevokeSettings → Developer → Revoke
RotateRevoke old key, create new key, update your integration

Keys can be created with no expiry or a fixed lifetime (30 days, 90 days, or 1 year); revoke any key that is no longer in use. For the full step-by-step on creating, scoping, monitoring, and revoking keys from the dashboard, see Managing API Keys.

StatusMeaning
401 authentication_errorNo Authorization: Bearer header, or the key is unknown, revoked, expired, belongs to a deactivated member, was sent to a different region, or is an sk_test_ key sent to production
403 authorization_errorThe key is valid but lacks a permission this operation requires (Missing permission: …)
  • Server-side only. Never embed API keys in browser JavaScript, mobile apps, or any client-side code. Keys are long-lived bearer tokens with full API access within their scopes.
  • Environment variables. Load keys from environment variables or a secrets manager at runtime.
  • Rotate on suspicion. If a key may have been exposed, revoke it immediately and issue a new one.
  • Scope minimally. A key used only for reading reservations needs view_reservations and should not have modify_tasks.