Skip to main content

Authorization and Scopes

Every API key is bound to one Remy merchant. Requests can only read or change resources owned by that merchant, including customer vouchers and rewards.

Scope model​

API keys have one or more scopes. An endpoint returns 403 when the key is valid but lacks its required scope. The required scope appears on every endpoint reference page.

Use a separate key for each integration so access can be revoked independently. Never use a key belonging to one merchant to identify or operate on another merchant's resources; cross-merchant identifiers return 404.

ScopeAccess
profile:readRead the merchant, integration, and granted scopes.
usage:readRead API usage totals and limits.
orders:readList and retrieve processed orders.
orders:writeSubmit completed orders.
customers:readRead customers, customer loyalty cards, and issued customer rewards.
customers:writeGive stamps, points, and rewards or adjust customer points.
rewards:readList and retrieve merchant reward templates.
rewards:writeUpdate customer reward coupon codes.
rewards:redeemRedeem customer rewards.
cards:readRead merchant loyalty-card templates.
vouchers:readRead merchant voucher templates and look up or download customer vouchers.
vouchers:issueIssue vouchers from existing merchant templates.
vouchers:redeemFully or partially redeem customer vouchers.
vouchers:manageCancel, adjust, and email customer vouchers.

Scopes are exact strings; one scope does not imply another. For example, vouchers:manage does not grant vouchers:read or vouchers:redeem.

Existing Zapier keys created before scoped access was introduced retain only their historical order-creation and reward-coupon-update access. Use a managed Developer API key for every other endpoint. New Developer API keys should receive only the scopes their integration needs; the merchant portal initially selects read-only scopes when creating a key.

Use GET /v1/public/me to inspect the scopes granted to the current key. A merchant administrator can change an active key's scopes immediately in Merchant Portal → Integrations → API. Scope changes do not change the secret.