Permissions reference

Every permission you can put on a StickyPrompts API key, what it unlocks in the REST API and the MCP server, and suggested sets for common integrations.

8 min read · Updated 28 September 2026

Permissions decide what an API key may do. You tick them when you create or edit a key in Settings > API keys, and you can change them later without rotating the key. A key never gets more than its owner has: permissions only narrow what you can already do in the app.

How permissions work

  • Each REST route accepts a list of permissions. The key needs at least one of them. The reference pages show them on every endpoint, and each links to its row below.
  • Each MCP tool needs exactly one permission. A key without it does not see the tool in tools/list, and calling it returns the same error as calling a tool that does not exist.
  • Permissions marked MCP work in both places. They gate at least one MCP tool as well as REST routes. All others are REST only. The same badge appears next to permissions in the app.
  • The three verbs. _get reads, _manage creates, updates and runs, _delete deletes. Delete is always separate, so you can give an integration write access without the power to remove things.
  • Workspace rules still apply. Model access, data residency and guardrails are enforced on every call, and integration connections keep their own access level (for example a database connection set to Read only accepts only SELECT, whatever the key holds).

When a key is missing a permission, REST answers:

HTTP 403
{"error": "This api key does not have any of the required permissions. You need at least one of: conversations_get"}

All permissions

Chat and conversations

PermissionWhat it unlocksMCP
conversations_getRead conversations and their messages, follow a conversation live over its WebSocket, list a conversation’s files, export messages. MCP: get_conversation, list_conversations.MCP
conversations_manageCreate conversations and send messages, fork, retry, share, compare models (sub-conversations), add or remove agents in a conversation. MCP: send_message.MCP
conversations_deleteDELETE /conversation/:id. MCP: delete_conversation.MCP
searchGET /search across your prompts and conversations. MCP: search.MCP

Prompts and runs

PermissionWhat it unlocksMCP
prompts_getList and read prompts, favorites, run history, instances, shares and prompt files. MCP: list_prompts, get_prompt.MCP
prompts_manageCreate, update, duplicate, move and share prompts; versions, favorites, instances and prompt files.-
prompts_deleteDELETE /prompt/:id.-
prompt_variables_managePOST /variable, PUT /variable/:id.-
prompt_variables_deleteDELETE /variable/:id.-
run_promptRun saved prompts and instances (POST /instance/:id/run, the /run/prompt/... shortcuts). MCP: run_prompt.MCP
custom_runPOST /run: send free text to a model without a saved prompt. MCP: custom_run.MCP
ai_models_getGET /ai_model, /ai_model/:id, /ai_model/filters, /ai_model/restricted. MCP: list_ai_models.MCP

Agents and workflows

PermissionWhat it unlocksMCP
agents_getGET /agents, GET /agents/:id. MCP: list_agents, get_agent.MCP
agents_managePOST /agents, PATCH /agents/:id.-
agents_deleteDELETE /agents/:id.-
workflow_tasks_getList and read workflow tasks and their executions. MCP: list_workflow_tasks, get_workflow_task.MCP
workflow_tasks_manageCreate and update workflow tasks, start a manual run. MCP: run_workflow_task.MCP
workflow_tasks_deleteDELETE /workflow-tasks/:id.-
mcp_getGET /mcp, GET /mcp/:id: your configured remote MCP servers (the ones agents and chats call out to).-
mcp_managePOST /mcp, PUT /mcp/:id.-
mcp_deleteDELETE /mcp/:id.-

Knowledge, files and spreadsheets

PermissionWhat it unlocksMCP
knowledge_bases_getList and read knowledge bases and folders. MCP: list_knowledge_bases, search_knowledge_base.MCP
knowledge_bases_manageCreate, update and share knowledge bases and folders; upload and delete knowledge-base files.-
knowledge_bases_deleteDELETE /knowledge-bases/:id.-
files_getGET /file. MCP: list_files, get_file.MCP
files_managePOST /file (upload), POST /file/:id/public.-
files_deleteDELETE /file/:id, DELETE /file/:id/public.-
spreadsheet_processing_getGET /xlsx/process-status/:taskId, GET /xlsx/history. MCP: list_spreadsheet_processing_tasks, get_spreadsheet_processing_task.MCP
spreadsheet_processing_manageStart, pause and resume spreadsheet processing. MCP: start_spreadsheet_processing, pause_spreadsheet_processing, resume_spreadsheet_processing.MCP

Projects, teams and workspace

PermissionWhat it unlocksMCP
projects_getList and read projects, pinned projects and project files. MCP: list_projects, get_project.MCP
projects_manageCreate, update, pin and share projects; project files. MCP: create_project.MCP
projects_deleteDELETE /project/:id. MCP: delete_project.MCP
teams_getGET /teams, /teams/all, /teams/:id/members. MCP: list_teams, list_team_members.MCP
teams_manageCreate and update teams; add, update and remove members.-
teams_deleteDELETE /teams/:id.-
organization_getGET /workspace. MCP: list_workspace_members.MCP
organization_managePATCH /workspace, PATCH /workspace/user/permissions.-
organization_deleteDELETE /workspace.-

Media generation and transcription

PermissionWhat it unlocksMCP
image_generation_managePOST /image_generation, POST /image_generation/edit. MCP: generate_image, edit_image.MCP
video_generation_getList video models, list and read video generations. MCP: get_video_generation_status.MCP
video_generation_manageCreate and retry video generations. MCP: generate_video.MCP
video_generation_deleteDelete a video generation. MCP: delete_video_generation.MCP
tts_generation_getList speech models, list and read speech generations. MCP: get_tts_generation_status.MCP
tts_generation_manageCreate and retry speech generations. MCP: generate_speech.MCP
tts_generation_deleteDelete a speech generation. MCP: delete_tts_generation.MCP
music_generation_getList music models, list and read music generations. MCP: get_music_generation_status.MCP
music_generation_manageCreate and retry music generations. MCP: generate_music.MCP
music_generation_deleteDelete a music generation. MCP: delete_music_generation.MCP
transcription_getList transcription models, list and read transcriptions. MCP: get_transcription_status.MCP
transcription_manageCreate and retry transcriptions, rename speakers. MCP: transcribe.MCP
transcription_deleteDelete a transcription. MCP: delete_transcription.MCP

Integrations

PermissionWhat it unlocksMCP
integrations_getGET /integration (the provider catalogue) and the SSH tunnel public key.-
integration_connections_getGET /integration/connections.-
integration_connections_manageConnect, reconnect and update connections.-
integration_connections_deleteDelete a connection.-
integration_email_getRead email connection info. MCP: list_email_connections.MCP
integration_email_manageSend email through a connected account. MCP: send_email.MCP
integration_crm_getCRM read routes (connection info, contacts, deals, lists, tags). MCP: list_crm_connections, search_crm_contacts, list_crm_contacts, search_crm_deals, list_crm_deals, list_crm_lists, list_crm_tags.MCP
integration_crm_manageCreate and edit CRM contacts, create deals. MCP: add_crm_contact, edit_crm_contact, create_crm_deal. The CRM connection itself must also allow write access.MCP
integration_database_getRead database schema and connection info. MCP: list_database_connections, list_database_tables, describe_database_tables.MCP
integration_database_manageRun a query on a connected database. MCP: run_database_query. What the query may do is set by the connection’s own permission level.MCP
integration_storage_getBrowse, search and read entries on a connected cloud drive. MCP: list_storage_connections, browse_storage_folder, search_storage_files, get_storage_entry.MCP
integration_storage_manageImport files from, and export files to, a connected cloud drive. MCP: import_storage_files, export_file_to_storage.MCP

Permissions that currently unlock nothing

You may see prompt_variables_get, prompt_categories_get, prompt_categories_manage, prompt_categories_delete, image_generation_get and image_generation_delete in the list. No customer-facing route or MCP tool uses them today, so ticking them has no effect.

Staff only, not grantable

statistics_get, ai_models_manage, invite_codes_get, invite_codes_manage and invite_codes_delete are reserved for StickyPrompts staff. They are hidden from the permission list, and a request to put them on a key is refused with 403 {"error":"You are using permissions that are restricted"}. This is why the MCP tool get_usage_statistics never appears for customer keys. Workspace usage is available to admins in the app under Usage, credits and billing.

Suggested permission sets

Start from one of these and add only what your integration turns out to need.

Read-only reporting bot

Answers questions from a database and your documents, writes nothing back.

PermissionsWhy
ai_models_get, custom_runPick a model and summarise the results.
integration_database_getFind the connection and read the schema.
integration_database_manageNeeded to run any query at all. Connect the database as Read only so only SELECT statements are accepted.
knowledge_bases_getSearch documents for context.

Chat bot

A front end (for example an internal Slack bot) that talks to your agents and knowledge.

PermissionsWhy
ai_models_getChoose the model for new conversations.
conversations_manage, conversations_getStart conversations, send messages and read replies.
agents_getFind agents to @mention or chat with.
knowledge_bases_getPass knowledge bases to a conversation.

Content generator

Fills in your saved prompts and produces text and images.

PermissionsWhy
ai_models_getChoose a model.
prompts_get, run_promptFind saved prompts and run them with variables.
custom_runOne-off generations without a saved prompt.
image_generation_manage, files_getGenerate images and look up the resulting files.

CRM assistant

Looks up contacts and deals, keeps the CRM up to date and sends follow-ups.

PermissionsWhy
integration_crm_getSearch and list contacts and deals.
integration_crm_manageAdd and edit contacts, create deals. The CRM connection must have Allow write access turned on.
integration_email_get, integration_email_manageFind the email connection and send the follow-up.
ai_models_get, custom_runDraft the email text.