Roles
Which permission each endpoint needs
Read endpoints —
GET /links, GET /links/{id}, GET /domains, GET /folders and GET /tags —
carry no permission guard. Any member of the workspace can call them, and a workspace whose plan no
longer includes Tags & Folders can still read the folders and tags it already has.Plan gates are separate
Holding the permission is not enough on its own. A call can still fail with403 because the
workspace’s plan does not include the feature or has exhausted a quota:
- Feature-gated — folders and tags need
tagsAndFolders; device targeting, geo targeting, link cloaking, scheduling and QR customisation each need their own feature on the plan. - Quota-limited — links, clicks, domains, team members, QR codes and password-protected links each count against a numeric plan maximum.