Skip to main content
Permissions grant an API key access to specific resources or allow it to take specific actions in Bachs. You can assign permissions to a key when creating or updating it in the dashboard. If your key doesn’t have the correct permissions, the API returns a 403 Forbidden error.

Permission types

Each permission targets a resource, like payments, customers, or products, and is one of two types:
  • resource:read: Read and list the resource. Applies to GET requests.
  • resource:write: Create, update, and delete the resource. Applies to POST, PATCH, and DELETE requests. Write permission automatically includes read.

Available permissions

Best practices

  • Follow the principle of least privilege.
    Only assign the permissions a key actually needs. A key used to sync product catalog data doesn’t need payments:write.
  • Create separate keys per integration or team.
    Issue a distinct key per system or team so you can revoke access without affecting others.
  • Review permissions when access requirements change.
    When access requirements change, update or rotate the key rather than leaving unused permissions in place.