Skip to main content
Every write endpoint is guarded by a named permission. Permissions are not assigned individually — they come from the caller’s role on their workspace membership. An API key inherits the permissions of the member who created it.

Roles

Which permission each endpoint needs

Read endpoints — GET /links, GET /links/{id}, GET /domains, GET /folders and GET /tags — carry no permission guard. Any member of the workspace can call them, and a workspace whose plan no longer includes Tags & Folders can still read the folders and tags it already has.

Plan gates are separate

Holding the permission is not enough on its own. A call can still fail with 403 because the workspace’s plan does not include the feature or has exhausted a quota:
  • Feature-gated — folders and tags need tagsAndFolders; device targeting, geo targeting, link cloaking, scheduling and QR customisation each need their own feature on the plan.
  • Quota-limited — links, clicks, domains, team members, QR codes and password-protected links each count against a numeric plan maximum.
The error message names which of the two applies.