On this page
A credential acts as a person#
A key or an agent acts as the person who created it, with that person’s current role in the workspace. If the person leaves the workspace their keys and OAuth codes are revoked. If their role is reduced, the credential loses the same abilities at once.
Approval is separate from all of this. Owner and Editor can approve in the interface; no credential can.
Scopes narrow a role#
Scopes are checked first, then the role. A scope can never grant what the role does not allow, and a role never grants what the scope does not carry.
The two refusals#
Site binding#
A key or an agent is bound to one site or, for a key an Owner makes, to the whole workspace. An agent is always bound to one site. A site-bound credential cannot see articles or briefs that belong to no site. Scopes and the site are fixed when the credential is made; to change them make a new one. Only the name and the daily cap can be edited.