Skip to content

OAuth permissions

Permissions are named OAuth scopes. A scope is necessary but never sufficient by itself: Stenz still checks subscription, connection policy, resource ownership, risk level, and current product state.

  • :read scopes allow bounded reads in one studio.
  • :write scopes allow changes in that domain; client-visible writes still require confirmation.
  • clients:pii reveals eligible client contact fields and is separate from ordinary client reads.
  • media:read permits eligible media access and does not make client content trusted.
  • deposits:refund and invoices:issue cover high-risk actions that still require a recent approval inside Stenz.
  • offline_access allows renewable authorization until the connection is paused, revoked, or otherwise invalidated.

Grant the smallest useful set, then reconnect or run consent again when you intentionally add a scope. Removing a scope can make a tool disappear without deleting the underlying studio data.

Connection identity

openid
Connection or optional field access
profile
Connection or optional field access
offline_access
Connection or optional field access

Studio resources

workspace:read
5 direct tools
requests:read
3 direct tools
requests:write
5 direct tools
forms:read
2 direct tools
forms:write
4 direct tools
flash:read
3 direct tools
flash:write
6 direct tools
clients:read
3 direct tools
clients:pii
3 direct tools
media:read
Connection or optional field access
messages:read
1 direct tools
messages:write
3 direct tools
calendar:read
6 direct tools
calendar:write
2 direct tools
bookings:write
5 direct tools
deposits:read
3 direct tools
deposits:write
3 direct tools
deposits:refund
1 direct tools
invoices:read
3 direct tools
invoices:write
2 direct tools
invoices:issue
4 direct tools
invoices:send
1 direct tools
automations:read
3 direct tools
automations:write
4 direct tools
audit:read
Connection or optional field access