onrup

Safety and governance

Scope

What is scope?

A scope is a named permission attached to a credential, such as reading datasets or creating deployments. Scopes implement least privilege: a credential carries only what its holder needs to do its job.

Read and write should be separate scopes for each resource, because the majority of integrations only need to read and the blast radius of a leak differs enormously between them.

Administrative actions are best kept off long-lived credentials entirely, so that changing billing or deleting data requires an interactive session rather than a key in a configuration file.

Related terms

All terms in the glossary →

Start with the free tier

A magic link creates your account, your tenant and your first API key. No card until you ask for compute.