Every key and OAuth grant is read or write. Each endpoint is marked with the access it needs.
| Access | Allows |
|---|---|
read | Every read |
write | Reads and writes |
Start an agent or new integration on read.
OAuth apps
An OAuth token is read or write too, and never does more than the person who granted it.
Acting as a creator
A partner's write key acts for its roster creators with Lucra-Account: crtr_…. See Partners.
Signed-in members
In the app, owners and admins can do everything; other members read everything but payments.
Not in the API
Team, settings, and agreements stay in the app. Card and bank details, identity checks, and platform sign-ins happen on hosted pages: POST /v1/connections returns the URL, and webhooks say when they're done.