Skip to content

Change an app's permissions

PATCH
/connections/{id}
curl --request PATCH \
--url https://example.com/connections/019205d1-6e7a-7c3b-9f6e-3a2b1c0d9e8f \
--header 'Content-Type: application/json' \
--cookie bottle.session_token=<bottle.session_token> \
--data '{ "scopes": [ "tenant:read" ] }'

The new set must be part of what this connection already holds. Adding a permission is a grant, and a grant belongs on the app’s own consent screen: whoever connected it reconnects to widen it.

id
required

UUID v7

string format: uuid
Example
019205d1-6e7a-7c3b-9f6e-3a2b1c0d9e8f

UUID v7

Media typeapplication/json
object
scopes
required
Array<string>
Allowed values: tenant:read tenant:write customers:read customers:write products:read products:write tax:read tax:write orders:read orders:write rounds:read rounds:write drivers:read drivers:write rota:read rota:write timeoff:write handovers:write deliveries:write cash:read cash:write stock:read stock:write invoices:read invoices:write members:read members:write invitations:read invitations:write keys:read keys:write connections:read connections:write shops:read shops:write billing:read billing:write privacy:read privacy:write accounting:read accounting:write setup:read setup:write emails:read console:read console:write console:owner

The connection as it now stands

Media typeapplication/json
object
id
required

UUID v7

string format: uuid
app
required
string
scopes
required
Array<string>
Allowed values: tenant:read tenant:write customers:read customers:write products:read products:write tax:read tax:write orders:read orders:write rounds:read rounds:write drivers:read drivers:write rota:read rota:write timeoff:write handovers:write deliveries:write cash:read cash:write stock:read stock:write invoices:read invoices:write members:read members:write invitations:read invitations:write keys:read keys:write connections:read connections:write shops:read shops:write billing:read billing:write privacy:read privacy:write accounting:read accounting:write setup:read setup:write emails:read console:read console:write console:owner
connectedBy
required
string | null
createdAt
required
string format: date-time
lastUsedAt
required
string | null format: date-time
Example
{
"id": "019205d1-6e7a-7c3b-9f6e-3a2b1c0d9e8f",
"app": "Claude",
"scopes": [
"tenant:read"
],
"connectedBy": "Joe Bloggs"
}

Not signed in

Media typeapplication/json
object
error
required
string
message
required
string
Example
{
"error": "not_found",
"message": "Customer not found"
}

Not allowed to manage connections, or asking for a key to do it

Media typeapplication/json
object
error
required
string
message
required
string
Example
{
"error": "not_found",
"message": "Customer not found"
}

No such connection in this business

Media typeapplication/json
object
error
required
string
message
required
string
Example
{
"error": "not_found",
"message": "Customer not found"
}

Asking for a permission the connection was never granted

Media typeapplication/json
object
error
required
string
message
required
string
Example
{
"error": "not_found",
"message": "Customer not found"
}