Skip to content

Developers

Permissions

Each token does only what it was granted: by area, resource and action.

The four layers

  1. Which data. A token only reaches the companies chosen when it was created: its primary account, other companies administered by whoever created it and, if chosen, whole groups, which include their subsidiaries (also those added later). Choosing one company does not add the rest of its group. Routes with a companyId check that the company is within that scope; otherwise they respond 403 or 404 without revealing anyone else's data. GET /auth/whoami returns the list of companies a token reaches (Getting started).
  2. What it can do. Permissions look like area:resource.action, for example sales:invoices.read. Each route requires one, and the token must hold a grant that covers it.
  3. Conditions. Expiry date, allowed IP addresses and access to personal data (Authentication).
  4. Quotas. Requests-per-minute limit for the token, within that of the account and the user (Rate limits).

Levels

When you create a token you choose a level for each area or resource:

LevelWhat it grants
NoneNothing.
ReadReads (read), including file downloads.
WriteRead, plus create, update and delete (create, update, delete). It does not include critical actions.
FullEverything above and the critical actions.

Write does not imply Read: the Write level on screen stores both grants, the read one and the write one.

Grant grammar

A token stores a list of grants. From the broadest to the most specific:

GrantOpensLevel
area:*The whole area, critical actions included.Full on the area
area:*.readThe area's reads.Read on the area
area:*.writeCreate, update and delete across the area, without critical actions.Write on the area
area:resource.*The whole resource, critical actions included.Full on the resource
area:resource.writeCreate, update and delete on the resource, without critical actions.Write on the resource
area:resource.actionOne specific action.Advanced

A client token only accepts grants that open permissions from the public catalogue. If a grant would open something internal to BMC, it is rejected in full rather than trimmed silently.

Critical actions

Beyond read, create, update and delete, some actions are irreversible or have an effect outside the platform: issuing an invoice, filing a return with the tax authority, sending a document to the end customer, voiding, merging, posting to the ledger or reconciling. These are the critical actions.

The Write level does not cover critical actions. Only Full (area:* or area:resource.*) or the exact action name, chosen under Advanced, opens them. They are flagged in the catalogue.

Complete catalogue

The public catalogue has 154 permissions across 14 areas and 50 resources; 28 are critical actions. Resources flagged "Personal data" return tax ID, IBAN, phone, date of birth or address, which come back masked if the token does not have the personal data permission. Adding a permission to the catalogue grants nothing to anyone: each token stores only what was chosen when it was created.

Contacts contacts:*

Resource Actions
Contacts
contacts:contacts.* Personal data
  • contacts:contacts.read Read
  • contacts:contacts.create Create
  • contacts:contacts.update Update
  • contacts:contacts.delete Delete
  • contacts:contacts.merge Merge Critical action
  • contacts:contacts.transition Change stage Critical action
Accounts and companies
contacts:accounts.* Personal data
  • contacts:accounts.read Read
  • contacts:accounts.create Create
  • contacts:accounts.update Update
  • contacts:accounts.delete Delete
  • contacts:accounts.merge Merge Critical action
Beneficial ownership and holdings
contacts:ownership.* Personal data
  • contacts:ownership.read Read
  • contacts:ownership.create Create
  • contacts:ownership.update Update
  • contacts:ownership.delete Delete

CRM and matters crm:*

Resource Actions
Matters
crm:cases.*
  • crm:cases.read Read
  • crm:cases.create Create
  • crm:cases.update Update
Appointments
crm:appointments.*
  • crm:appointments.read Read
  • crm:appointments.create Create
  • crm:appointments.update Update
  • crm:appointments.cancel Cancel Critical action
Support tickets
crm:tickets.*
  • crm:tickets.read Read
  • crm:tickets.create Create
  • crm:tickets.update Update
  • crm:tickets.delete Delete

Sales sales:*

Resource Actions
Invoices, proformas and credit notes
sales:invoices.*
  • sales:invoices.read Read
  • sales:invoices.create Create
  • sales:invoices.update Update
  • sales:invoices.delete Delete
  • sales:invoices.issue Issue Critical action
  • sales:invoices.send Send Critical action
  • sales:invoices.pay Record payment Critical action
  • sales:invoices.void Void Critical action
  • sales:invoices.import Import history Critical action
Issuer profiles and series
sales:issuer_profiles.*
  • sales:issuer_profiles.read Read
  • sales:issuer_profiles.create Create
  • sales:issuer_profiles.update Update
Service catalogue
sales:services.*
  • sales:services.read Read
  • sales:services.create Create
  • sales:services.update Update

Purchases purchases:*

Resource Actions
Supplier invoices and expenses
purchases:documents.*
  • purchases:documents.read Read
  • purchases:documents.create Create
  • purchases:documents.update Update
  • purchases:documents.delete Delete
  • purchases:documents.import Import history Critical action
  • purchases:documents.post Post to ledger Critical action
Suppliers
purchases:suppliers.* Personal data
  • purchases:suppliers.read Read
  • purchases:suppliers.create Create
  • purchases:suppliers.update Update
Remittances
purchases:remittances.*
  • purchases:remittances.read Read
  • purchases:remittances.create Create
  • purchases:remittances.send Send Critical action

Accounting accounting:*

Resource Actions
Journal
accounting:journal.*
  • accounting:journal.read Read
  • accounting:journal.create Create
  • accounting:journal.update Update
  • accounting:journal.delete Delete
  • accounting:journal.post Post to ledger Critical action
Chart of accounts
accounting:ledger_accounts.*
  • accounting:ledger_accounts.read Read
  • accounting:ledger_accounts.create Create
  • accounting:ledger_accounts.update Update
Fixed assets
accounting:fixed_assets.*
  • accounting:fixed_assets.read Read
  • accounting:fixed_assets.create Create
  • accounting:fixed_assets.update Update
  • accounting:fixed_assets.delete Delete
Fiscal years
accounting:fiscal_years.*
  • accounting:fiscal_years.read Read
  • accounting:fiscal_years.create Create
  • accounting:fiscal_years.close Close year Critical action
Opening balances
accounting:opening_balances.*
  • accounting:opening_balances.read Read
  • accounting:opening_balances.create Create
Reports (P&L, balance sheet, ledger)
accounting:reports.*
  • accounting:reports.read Read
  • accounting:reports.export Export Critical action

Treasury treasury:*

Resource Actions
Bank accounts
treasury:bank_accounts.* Personal data
  • treasury:bank_accounts.read Read
  • treasury:bank_accounts.create Create
  • treasury:bank_accounts.update Update
Bank movements
treasury:bank_movements.*
  • treasury:bank_movements.read Read
  • treasury:bank_movements.create Create
  • treasury:bank_movements.import Import history Critical action
Cash flow
treasury:cashflow.*
  • treasury:cashflow.read Read
Reconciliation
treasury:reconciliation.*
  • treasury:reconciliation.read Read
  • treasury:reconciliation.create Create
  • treasury:reconciliation.update Update
  • treasury:reconciliation.reconcile Reconcile Critical action

Tax tax:*

Resource Actions
Obligations and calendar
tax:obligations.*
  • tax:obligations.read Read
Tax profile
tax:profile.*
  • tax:profile.read Read
  • tax:profile.update Update
Tax returns and receipts
tax:returns.*
  • tax:returns.read Read
  • tax:returns.create Create
  • tax:returns.update Update
  • tax:returns.submit Submit Critical action
SII (immediate VAT reporting)
tax:sii.*
  • tax:sii.read Read
  • tax:sii.submit Submit Critical action
VAT record books
tax:ledger_books.*
  • tax:ledger_books.read Read
  • tax:ledger_books.create Create
Counterparties (347, 349)
tax:counterparties.* Personal data
  • tax:counterparties.read Read
  • tax:counterparties.create Create
Annual renewals
tax:renewals.*
  • tax:renewals.read Read
  • tax:renewals.create Create
  • tax:renewals.update Update
Government notices
tax:notices.*
  • tax:notices.read Read
  • tax:notices.update Update
  • tax:notices.acknowledge Record access Critical action

Payroll and HR payroll:*

Resource Actions
Employees
payroll:workers.* Personal data
  • payroll:workers.read Read
  • payroll:workers.create Create
  • payroll:workers.update Update
Social security employer accounts
payroll:contribution_accounts.*
  • payroll:contribution_accounts.read Read
  • payroll:contribution_accounts.create Create
  • payroll:contribution_accounts.delete Delete
Social security (RED)
payroll:social_security.*
  • payroll:social_security.read Read
  • payroll:social_security.submit Submit Critical action

Documents documents:*

Resource Actions
Files
documents:files.*
  • documents:files.read Read
  • documents:files.create Create
  • documents:files.update Update
  • documents:files.delete Delete
Data room
documents:data_room.*
  • documents:data_room.read Read
  • documents:data_room.create Create
  • documents:data_room.update Update
Upload links
documents:upload_links.*
  • documents:upload_links.read Read
  • documents:upload_links.create Create
  • documents:upload_links.update Update
Document capture
documents:ingest.*
  • documents:ingest.read Read
  • documents:ingest.create Create
  • documents:ingest.update Update

E-signature sign:*

Resource Actions
Signature envelopes
sign:envelopes.*
  • sign:envelopes.read Read
  • sign:envelopes.create Create
  • sign:envelopes.update Update
  • sign:envelopes.send Send Critical action
  • sign:envelopes.void Void Critical action
  • sign:envelopes.reissue Reissue Critical action
Evidence and signed PDFs
sign:evidence.*
  • sign:evidence.read Read
Code verification
sign:verification.*
  • sign:verification.read Read
Certified communications
sign:certified_mail.*
  • sign:certified_mail.read Read
  • sign:certified_mail.send Send Critical action

Tax doctrine and law knowledge:*

Resource Actions
DGT binding rulings
knowledge:dgt.*
  • knowledge:dgt.read Read
Official Gazette (BOE)
knowledge:boe.*
  • knowledge:boe.read Read
Search
knowledge:search.*
  • knowledge:search.read Read

Connectors connectors:*

Resource Actions
Payment provider payouts
connectors:payouts.*
  • connectors:payouts.read Read
  • connectors:payouts.create Create
  • connectors:payouts.post Post to ledger Critical action

Account account:*

Resource Actions
Notifications
account:notifications.*
  • account:notifications.read Read
  • account:notifications.update Update
Onboarding
account:onboarding.*
  • account:onboarding.read Read
  • account:onboarding.update Update

Developers developers:*

Resource Actions
Credentials
developers:tokens.*
  • developers:tokens.read Read
  • developers:tokens.create Create
  • developers:tokens.update Update
  • developers:tokens.delete Delete
  • developers:tokens.rotate Rotate Critical action
Webhooks
developers:webhooks.*
  • developers:webhooks.read Read
  • developers:webhooks.create Create
  • developers:webhooks.update Update
  • developers:webhooks.delete Delete
  • developers:webhooks.test Send test Critical action
API usage
developers:usage.*
  • developers:usage.read Read
Email
Contact