Skip to content

Scope reference

Gateway defines 226 permission scopes. The tables below list their exact names and the actions they authorize. Assign permissions through groups or a user’s additional permissions; see users and groups and API tokens, OAuth, and MCP for setup.

  • Restrictions: Resource means the scope supports a resource qualifier; Folder means it also supports a folder qualifier. — means the base scope has no resource qualifier.
  • Tokens: API means the scope can be delegated to an API token or OAuth for the Gateway API; MCP means it can be delegated to OAuth for the Gateway MCP resource. — means neither regular token family accepts it. User permissions and token permissions are not interchangeable.
  • A permission does not enable an unavailable product feature, bypass license requirements, or grant credentials or privileges at the external provider.
  • Delegated access is limited by the owning user’s current effective permissions. MCP scope eligibility does not mean a corresponding tool exists.
  • inference:setup is a special OAuth scope for Inference setup, not an ordinary user or group permission.

A base permission such as proxy:view covers all routes. A qualified permission such as proxy:view:<routeId> covers one route; proxy:view:folder/<folderId> covers routes in the selected folder.

The qualifier depends on the resource type. Docker container scopes use <nodeId> for a node or <nodeId>/<stableResourceId> for a specific container or deployment. Qualified Pages permissions use the project ID, including operations on its deployments, tags, and deployment tokens. Select the target in the permissions editor rather than using an ID from another resource type.

For creation permissions, a folder restriction selects the destination folder, not a resource that has not been created yet. Folder management and resource operations are separate permissions: managing a folder does not itself grant access to every item in it.

Create-only and delete-only permissions do not grant list visibility by themselves. Matching write permissions can imply read access while preserving their resource boundary.

Scope Description Restrictions Tokens
pki:ca:view:root View root certificate authorities — API, MCP
pki:ca:view:intermediate View intermediate certificate authorities — API, MCP
pki:ca:create:root Create new root certificate authorities — API, MCP
pki:ca:create:intermediate Create intermediate CAs under a root Resource API, MCP
pki:ca:revoke:root Revoke root certificate authorities — API, MCP
pki:ca:revoke:intermediate Revoke intermediate certificate authorities — API, MCP
Scope Description Restrictions Tokens
pki:cert:view View issued certificates Resource API, MCP
pki:cert:issue Issue new certificates Resource API, MCP
pki:cert:revoke Revoke issued certificates Resource API, MCP
pki:cert:export Export certificates and keys Resource API, MCP
Scope Description Restrictions Tokens
pki:templates:view View certificate templates — API, MCP
pki:templates:create Create certificate templates — API, MCP
pki:templates:edit Edit certificate templates — API, MCP
pki:templates:delete Delete certificate templates — API, MCP
Scope Description Restrictions Tokens
domains:view View managed domains Resource, Folder API, MCP
domains:create Create managed domains Resource, Folder API, MCP
domains:edit Edit managed domains Resource, Folder API, MCP
domains:delete Delete managed domains Resource, Folder API, MCP
domains:folders:manage Organize managed domains into folders — API, MCP
Scope Description Restrictions Tokens
proxy:view View and search ingress routes Resource, Folder API, MCP
proxy:create Create new ingress routes Resource, Folder API, MCP
proxy:edit Edit ingress route configuration Resource, Folder API, MCP
proxy:delete Delete ingress routes Resource, Folder API, MCP
proxy:raw:read View raw nginx configuration Resource, Folder —
proxy:raw:write Edit raw nginx configuration Resource, Folder —
proxy:raw:toggle Switch between managed and raw config mode Resource, Folder —
proxy:raw:bypass Save raw nginx config without dangerous directive restrictions Resource, Folder —
proxy:advanced Use advanced proxy configuration Resource, Folder API, MCP
proxy:advanced:bypass Save unrestricted advanced nginx snippets Resource, Folder —
proxy:maintenance:bypass Create temporary access codes for maintained routes Resource, Folder —
proxy:folders:manage Create, reorder, and remove route folders — API, MCP
Scope Description Restrictions Tokens
pages:view View Page Projects, Deployments, Tags, previews, and usage Resource, Folder API, MCP
pages:create Create static Page Projects Resource, Folder API, MCP
pages:edit Rename Page Projects and edit their retention and quota settings Resource, Folder API, MCP
pages:delete Delete eligible Page Projects Resource, Folder API, MCP
pages:deploy Create and upload static Deployments Resource, Folder API, MCP
pages:deployments:manage Pin, unpin, clean up, and delete eligible Deployments Resource, Folder API, MCP
pages:tags:manage Create, move, and delete Page Project Tags Resource, Folder API, MCP
pages:tokens:manage Create, restrict, and revoke Project deploy credentials Resource, Folder API, MCP
pages:folders:manage Create, reorder, and remove Page Project folders — API, MCP
pages:settings:view View wildcard profile and storage defaults — API, MCP
pages:settings:edit Configure and migrate the wildcard Pages profile and storage defaults — API, MCP
Scope Description Restrictions Tokens
proxy:templates:view View nginx templates Resource API, MCP
proxy:templates:create Create nginx templates — API, MCP
proxy:templates:edit Edit nginx templates Resource API, MCP
proxy:templates:delete Delete nginx templates Resource API, MCP
Scope Description Restrictions Tokens
ssl:cert:view View SSL certificates Resource, Folder API, MCP
ssl:cert:issue Provision ACME or upload SSL certificates Resource, Folder API, MCP
ssl:cert:folders:manage Organize SSL certificates into folders — API, MCP
ssl:cert:delete Delete SSL certificates Resource, Folder API, MCP
ssl:cert:revoke Revoke SSL certificates Resource, Folder API, MCP
ssl:cert:export Export SSL certificates Resource, Folder API, MCP
Scope Description Restrictions Tokens
acl:view View access control lists Resource API, MCP
acl:create Create access control lists — API, MCP
acl:edit Edit access control lists Resource API, MCP
acl:delete Delete access control lists Resource API, MCP
Scope Description Restrictions Tokens
nodes:details View managed nodes Resource, Folder API, MCP
nodes:create Enroll new nodes Resource, Folder API, MCP
nodes:rename Rename nodes Resource, Folder API, MCP
nodes:delete Remove nodes Resource, Folder API, MCP
nodes:config:view View node nginx configuration Resource, Folder —
nodes:config:edit Edit node nginx configuration Resource, Folder —
nodes:logs View node daemon and nginx logs Resource, Folder API, MCP
nodes:console Open interactive shell on nodes Resource, Folder API, MCP
nodes:files:read Browse, open, copy, and download node files Resource, Folder API, MCP
nodes:files:write Create, edit, upload, move, and delete node files Resource, Folder API, MCP
nodes:lock Prevent new proxy hosts or containers on selected nodes Resource, Folder API, MCP
nodes:folders:manage Create, reorder, and remove node folders — API, MCP
Scope Description Restrictions Tokens
admin:users Create, edit, and delete users Resource, Folder —
admin:users:impersonate Temporarily act as another active user Resource, Folder —
admin:users:folders:manage Create, reorder, and remove user folders — API, MCP
admin:groups Create, edit, and delete permission groups Resource, Folder —
admin:groups:folders:manage Create, reorder, and remove permission group folders — API, MCP
admin:audit View the audit log — API, MCP
audit:siem:view View SIEM destinations and audit delivery history — API, MCP
audit:siem:manage Configure SIEM destinations and control audit deliveries — API, MCP
admin:system System-level administration (protected) — —
admin:details:certificates View internal system PKI and SSL certificates in read-only mode — API, MCP
admin:update Check for and apply updates — API, MCP
admin:alerts View and manage alerts — API, MCP
Scope Description Restrictions Tokens
settings:gateway:view View sign-in provisioning and external control-plane settings — —
settings:gateway:edit Edit sign-in provisioning and external control-plane settings — —
Scope Description Restrictions Tokens
integrations:gitlab:view View configured GitLab connectors and sync status — API, MCP
integrations:gitlab:manage Create, edit, rotate, and delete GitLab connectors — —
integrations:gitlab:sync Refresh projects and registries using the connector credential — API
integrations:gitlab:system Use the connector credential for otherwise permitted GitLab operations — —
integrations:gitlab:projects:view Discover allowed GitLab groups and projects — API, MCP
integrations:gitlab:repo:read Read repository trees and files through GitLab connectors — API, MCP
integrations:gitlab:repo:write Commit file changes through GitLab connectors — API
integrations:gitlab:ci:view View GitLab CI pipelines and configuration — API
integrations:gitlab:ci:edit Lint and update GitLab CI configuration — API
integrations:gitlab:variables:view View GitLab variable metadata without secret values — API
integrations:gitlab:variables:edit Create and update GitLab project variables — API
integrations:gitlab:variables:delete Delete GitLab project variables — API
integrations:gitlab:webhooks:manage Create, update, and delete GitLab project webhooks — API
integrations:gitlab:registry:manage Manage GitLab registry integration records and deploy credentials — API
integrations:gitlab:sandbox:clone Clone allowed GitLab repositories into AI sandboxes — API
Scope Description Restrictions Tokens
integrations:github:view View configured GitHub token connectors — API, MCP
integrations:github:manage Create, edit, rotate, and delete GitHub token connectors — —
integrations:github:system Use the connector credential instead of a personal GitHub authorization — —
Scope Description Restrictions Tokens
integrations:git:view View configured generic Git connectors — API, MCP
integrations:git:manage Create, edit, rotate, and delete generic Git connectors — —
integrations:git:system Use the connector credential instead of a personal Git authorization — —
Scope Description Restrictions Tokens
integrations:ssh:view View configured external SSH servers — API, MCP
integrations:ssh:manage Add and configure external SSH servers and jump hosts — —
integrations:ssh:use Execute approved commands on configured external SSH servers — API
Scope Description Restrictions Tokens
integrations:cloudflare:view View configured Cloudflare connectors and synchronization status — API, MCP
integrations:cloudflare:manage Create, edit, test, synchronize, rotate, and delete Cloudflare connectors — —
Scope Description Restrictions Tokens
integrations:hosting:view View hosting accounts and connection status Resource API, MCP
integrations:hosting:manage Connect, configure and synchronize hosting accounts Resource —
hosting:resources:view View provider inventory and associated Gateway nodes Resource API, MCP
hosting:resources:create Order provider VMs and install Gateway roles; may incur charges Resource —
hosting:resources:power Start, shut down and reboot VMs; all hosted roles are affected Resource —
hosting:resources:resize Change VM resources; may change provider charges Resource —
hosting:snapshots:view View provider snapshots and snapshot folders without changing the VM Resource API, MCP
hosting:snapshots:create Create provider snapshots; storage may incur charges Resource —
hosting:snapshots:delete Permanently delete provider snapshots Resource —
hosting:snapshots:restore Replace current VM data with a snapshot Resource —
hosting:snapshots:folders:manage Create snapshot folders and move snapshots between folders Resource —
hosting:resources:delete Destroy provider VM data or cancel HOSTKEY rental Resource —
hosting:resources:recover Restart Gateway daemons or explicitly retry a failed installation Resource —
hosting:billing:view View account balance, charges, invoices and transactions Resource —
hosting:billing:topup Create HOSTKEY deposit invoices; payment remains provider-hosted Resource —
Scope Description Restrictions Tokens
housekeeping:view View housekeeping configuration, stats, and run history — API, MCP
housekeeping:run Manually run housekeeping tasks — API, MCP
housekeeping:configure Edit housekeeping configuration and schedule — API, MCP
Scope Description Restrictions Tokens
license:view View Gateway license status and entitlement details — API, MCP
license:manage Activate, update, or remove the Gateway license — API, MCP
Scope Description Restrictions Tokens
ai:workspace:use Use the AI Workspace interface and embedded assistant — —
feat:ai:use Use Gateway Inference and view personal inference usage — —
feat:ai:configure Configure AI settings and providers — —
ai:skills:manage Create, edit, enable, disable, and delete AI Workspace skills — —
ai:sandbox:use Run bounded AI sandbox jobs — —
ai:sandbox:tier:medium Run AI sandbox jobs with medium resource limits — —
ai:sandbox:tier:high Run AI sandbox jobs with high resource limits — —
ai:sandbox:manage View and kill AI sandbox jobs — —
mcp:use Allow this user account to access the remote MCP server with OAuth — —
Scope Description Restrictions Tokens
inference:setup OAuth-only authorization for the companion CLI Inference setup resource; not assignable to users or custom groups — —
inference:providers:view View inference providers, connections, discovery, and quota — —
inference:providers:manage Connect, update, synchronize, route, and disconnect inference providers — —
inference:models:manage Create, publish, replace, and delete inference models — —
inference:limits:manage Configure default and per-user inference budgets — —
inference:usage:view View system-wide and per-user inference usage — —
Scope Description Restrictions Tokens
docker:containers:view View Docker containers Resource, Folder API, MCP
docker:containers:create Create and duplicate containers Resource, Folder API, MCP
docker:containers:edit Edit container settings and configuration Resource, Folder API, MCP
docker:containers:config View container recreate/configuration fields Resource, Folder API, MCP
docker:containers:manage Start, stop, restart, kill, and recreate containers Resource, Folder API, MCP
docker:containers:environment Modify container environment variables Resource, Folder API, MCP
docker:containers:delete Remove containers Resource, Folder API, MCP
docker:containers:console Open interactive console in containers Resource, Folder API, MCP
docker:containers:files:read Browse and read files in containers Resource, Folder API, MCP
docker:containers:files:write Create, edit, move, and delete files in containers Resource, Folder API, MCP
docker:containers:export Export portable container archives Resource, Folder API, MCP
docker:containers:secrets View and manage encrypted secrets Resource, Folder API, MCP
docker:containers:webhooks View and manage container webhook update triggers Resource, Folder API, MCP
docker:containers:mounts Add, remove, or change container and deployment mounts Resource, Folder API, MCP
docker:containers:migrate Migrate containers and deployments between Docker nodes Resource, Folder API, MCP
docker:availability:manage Enable, scale, heal, and disable multi-node workload Availability Resource, Folder API, MCP
docker:containers:folders:manage Create, reorder, and remove Docker resource folders — API, MCP
Scope Description Restrictions Tokens
docker:compose:view Discover and inspect Compose projects, services, monitoring, logs, revisions, and activity Resource, Folder API, MCP
docker:compose:create Validate and deploy managed Compose projects; adoption also requires Manage Compose Projects Resource, Folder API, MCP
docker:compose:manage Adopt projects and manage lifecycle, revisions, secrets, and bindings Resource, Folder API, MCP
docker:compose:delete Delete Compose projects or run destructive down/delete-volume actions Resource, Folder API, MCP
Scope Description Restrictions Tokens
docker:images:view View Docker images Resource, Folder API, MCP
docker:images:pull Pull Docker images Resource, Folder API, MCP
docker:images:delete Remove and prune Docker images Resource, Folder API, MCP
Scope Description Restrictions Tokens
docker:volumes:view View Docker volumes Resource, Folder API, MCP
docker:volumes:create Create Docker volumes Resource, Folder API, MCP
docker:volumes:delete Remove Docker volumes Resource, Folder API, MCP
docker:volumes:export Export portable Docker volume archives Resource, Folder API, MCP
docker:volumes:files:read Browse, open, and download Docker volume files Resource, Folder API, MCP
docker:volumes:files:write Create, edit, upload, move, and delete Docker volume files Resource, Folder API, MCP
Scope Description Restrictions Tokens
docker:networks:view View Docker networks Resource, Folder API, MCP
docker:networks:create Create Docker networks Resource, Folder API, MCP
docker:networks:edit Connect and disconnect containers Resource, Folder API, MCP
docker:networks:delete Remove Docker networks Resource, Folder API, MCP
Scope Description Restrictions Tokens
docker:registries:view View Docker registries — API, MCP
docker:registries:create Add Docker registries — API, MCP
docker:registries:edit Edit Docker registry settings — API, MCP
docker:registries:delete Remove Docker registries — API, MCP
docker:registries:internal:pull Pull from all internal registry repositories or selected repository scopes Resource API, MCP
docker:registries:internal:push Push to all internal registry repositories or selected repository scopes Resource API, MCP
Scope Description Restrictions Tokens
docker:tasks View Docker task progress Resource API, MCP
docker:tasks:manage Force-cancel active Docker tasks Resource API, MCP
Scope Description Restrictions Tokens
databases:view View saved database connections Resource, Folder API, MCP
databases:create Create saved database connections Resource, Folder API, MCP
databases:edit Edit saved database connections Resource, Folder API, MCP
databases:delete Delete saved database connections Resource, Folder API, MCP
databases:query:read Browse tables, keys, and run read-only database queries Resource, Folder API, MCP
databases:query:write Insert, update, delete, and run write queries against databases Resource, Folder API, MCP
databases:query:admin Run administrative or DDL database commands Resource, Folder API, MCP
databases:credentials:reveal Reveal saved database credentials and connection strings Resource, Folder API, MCP
databases:folders:manage Create, reorder, and remove database folders — API, MCP
Scope Description Restrictions Tokens
notifications:alerts:view View notification alert rules — API, MCP
notifications:alerts:create Create notification alert rules — API, MCP
notifications:alerts:edit Edit notification alert rules — API, MCP
notifications:alerts:delete Delete notification alert rules — API, MCP
notifications:webhooks:view View notification webhooks — API, MCP
notifications:webhooks:create Create notification webhooks — API, MCP
notifications:webhooks:edit Edit notification webhooks — API, MCP
notifications:webhooks:delete Delete notification webhooks — API, MCP
notifications:deliveries:view View webhook delivery attempts — API, MCP
notifications:view Read notification resources across alerts, webhooks, and deliveries — API, MCP
notifications:manage Full management access to alerts, webhooks, and deliveries — API, MCP
Scope Description Restrictions Tokens
logs:environments:view View external logging environments Resource, Folder API, MCP
logs:environments:create Create logging environments Resource, Folder API, MCP
logs:environments:edit Edit logging environments and schemas Resource, Folder API, MCP
logs:environments:delete Delete logging environments Resource, Folder API, MCP
logs:environments:folders:manage Create, reorder, and remove logging environment folders — API, MCP
logs:tokens:view View logging ingest tokens Resource API, MCP
logs:tokens:create Create logging ingest tokens Resource API, MCP
logs:tokens:delete Revoke logging ingest tokens Resource API, MCP
logs:schemas:view View reusable logging schemas Resource, Folder API, MCP
logs:schemas:create Create reusable logging schemas Resource, Folder API, MCP
logs:schemas:edit Edit reusable logging schemas Resource, Folder API, MCP
logs:schemas:delete Delete reusable logging schemas Resource, Folder API, MCP
logs:schemas:folders:manage Create, reorder, and remove logging schema folders — API, MCP
logs:read Search and inspect external logs Resource, Folder API, MCP
logs:manage Full access to external logging — API, MCP
Scope Description Restrictions Tokens
status-page:view View status page configuration, exposed services, incidents, and preview — API, MCP
status-page:manage Edit status page settings and exposed services — API, MCP
status-page:incidents:create Create manual incidents and promote automatic incidents — API, MCP
status-page:incidents:update Edit incident details and post incident timeline updates — API, MCP
status-page:incidents:resolve Resolve active status page incidents — API, MCP
status-page:incidents:delete Delete resolved status page incidents — API, MCP