VYG Docs

Scopes

Choose permissions for your API key or AI assistant.

Scopes are permissions for actions such as reading customers or editing campaigns. Each operation lists its accepted scopes; any one is enough. Missing permissions return 403 insufficient_scope.

  • API keys carry the scopes chosen when the key was created, from the permissions available for that key. See API keys.
  • Sign-in (OAuth) tokens carry the scopes granted at sign-in. See Authentication.

Scope shortcuts for sign-in

A client that signs in can ask for these shortcuts instead of listing scopes one by one. Use individual scope names when requesting only specific permissions.

ShortcutGrants
mcp:toolsEvery non-admin scope an MCP tool uses. Also the default when a client asks for no scope.
mcp:readThe :read scopes from that set.
mcp:writeThe :write scopes from that set.

Admin scopes (keys:manage, shopify:admin, klaviyo:admin) are granted only when the person signing in is a brand admin, and only when asked for by name.

All scopes

"Allows" names the MCP tools and, for operations without a listed tool, the REST routes. Each tool links to its REST route in the tool catalog.

ScopeAllowsAPI keyNotes
brand:readget_brandYes (vyg_ keys)
campaigns:readget_event_journey, list_campaigns, compare_campaigns, get_campaign_composer_options, get_campaign, list_campaign_activity, list_message_variantsYes (vyg_ keys)
campaigns:writecreate_campaign, get_campaign_composer_options, rename_campaign, update_campaign_schedule, update_campaign_messages, update_campaign, set_campaign_status, add_message_variant, update_message_variantNoSign-in only.
commerce:readlist_orders, get_order, list_subscriptions, get_subscription, list_products, get_productYes (vyg_ keys)
contacts:readGET /v1/contacts, GET /v1/contacts/{id}Yes (vyg_, vyg_ba_ keys)
conversations:readsearch_conversations, list_conversations, get_conversation_details, get_conversation_trace, GET /v1/conversations/{id}, GET /v1/conversations/{id}/messagesYes (vyg_, vyg_ba_ keys)
customers:readlist_customer_fields, list_customers, search_customers, get_customer, get_customer_activity, list_customer_orders, list_customer_subscriptionsYes (vyg_ keys)
discounts:writecreate_discount, update_discountNoSign-in only.
events:readlist_event_typesYes (vyg_ keys)
insights:readget_lifetime_value, get_lifetime_value_by_year, get_rfm_tiers, get_top_products, list_at_risk_customers, get_lifecycle_stages, get_customer_overview, get_product_performance, get_first_products, get_acquisition_sources, list_conversation_insights, list_insight_conversationsYes (vyg_ keys)
integrations:readlist_integrationsYes (vyg_ keys)
keys:managePOST /v1/keys, GET /v1/keys, POST /v1/keys/{id}/rotate, DELETE /v1/keys/{id}NoRequires a brand administrator. Sign-in only.
klaviyo:adminread_klaviyo, write_klaviyo, search_klaviyo_docsNoRequires a brand administrator. Sign-in only.
klaviyo:readread_klaviyo, search_klaviyo_docsNoSign-in only.
providers:readlist_providers, get_provider, list_event_definitions, get_event_definitionYes (vyg_ba_ keys)
providers:writecreate_provider, update_provider, create_event_definition, update_event_definitionYes (vyg_ba_ keys)
segments:readlist_customer_segments, list_segments, estimate_segment, get_segment, get_segment_audience, list_segment_members, list_segment_historyYes (vyg_ keys)
segments:writecreate_segment, update_segment, archive_segmentNoSign-in only.
shopify:adminread_shopify, mutate_shopify, learn_shopify_api, search_shopify_docs, validate_shopify_graphqlNoRequires a brand administrator. Sign-in only.
shopify:readread_shopify, learn_shopify_api, search_shopify_docs, validate_shopify_graphqlNoSign-in only.
stats:readget_performance_statsYes (vyg_ keys)

On this page