---
title: "Scoped API tokens"
description: "API tokens can now be restricted to the resources they need, such as links:read or visitors:write. Built for AI agents and single-purpose integrations."
canonical: "https://linkbreakers.com/help/article/scoped-api-tokens"
last-updated: 2026-10-10
---

# Scoped API tokens

> API tokens can now be restricted to the resources they need, such as links:read or visitors:write. Built for AI agents and single-purpose integrations.

## Short answer

You can now restrict a Linkbreakers API token to the resources it needs instead of giving it full access to your workspace. Pick read or read and write per resource when you create a token, or edit an existing one. Every endpoint declares the scope it requires, so agents and SDKs can ask for exactly the access they need.

## What we shipped

### Least-privilege tokens

Each token now has either **full access** or a list of **scopes** such as `links:read`, `analytics:read` or `webhooks:write`. A scoped token can only call the endpoints its scopes cover. Anything else is refused with a `403` that names the missing scope.

Your existing tokens are untouched: they keep full access, and full access keeps covering any scope we add later.

### Scopes in the dashboard

On [**Dashboard → API Tokens**](https://app.linkbreakers.com/workspace/dashboard/api-tokens), creating a secret key now asks for its access: full, or restricted to the resources you choose. The token list shows what each token can do, and **Edit access** changes it without issuing a new token.

### Scopes machines can read

The scopes are published where tools look for them:

- The [OpenAPI specification](https://api.linkbreakers.com/internal/openapi/api/v1/api.swagger.json) declares the scope each operation requires and lists every scope in an `oauth2` security scheme
- `GET /v1/api-scopes` returns every scope with its description
- `https://api.linkbreakers.com/.well-known/oauth-protected-resource` serves RFC 9728 metadata with `scopes_supported`

MCP clients connecting through OAuth can request the same scopes, and the token they receive is limited to them on both the MCP server and the REST API.

Read the full guide: [API token scopes](/help/article/api-token-scopes).

## Frequently asked questions

### Do I need to change anything?

No. Existing tokens keep full access. Restrict a token when you want to.

### Which scope should I give an AI agent?

Only what its task needs. An agent that reports on campaigns needs `links:read` and `analytics:read`; it does not need to delete links or manage webhooks.

### Does a write scope include reading?

Yes. `links:write` also allows everything `links:read` does.
