> ## Documentation Index
> Fetch the complete documentation index at: https://docs.marro.si/llms.txt
> Use this file to discover all available pages before exploring further.

# Keys and scopes

> What each scope allows, and how to rotate and revoke keys.

A key belongs to your organization, not to a person. It can do exactly what its scopes allow, and only for modules your organization's subscription includes.

## Scopes

| Scope | Name | Allows | Endpoints |
| - | - | - | - |
| `leads.read` | Read leads | Leads with every field, and the lists that describe them: fields, stages, sources and people. | [List leads](/api-reference/leads/list-leads), [Get a lead](/api-reference/leads/get-lead), [List lead fields](/api-reference/reference/list-fields), [List stages](/api-reference/reference/list-stages), [List pipelines](/api-reference/reference/list-pipelines), [List sources](/api-reference/reference/list-sources), [List people](/api-reference/reference/list-users) |
| `leads.write` | Create and update leads | Create leads, change their fields, stage and owner, and add notes. Needs leads.read. | [Create a lead](/api-reference/leads/create-lead), [Capture a lead](/api-reference/leads/capture-lead), [Update a lead](/api-reference/leads/update-lead), [Add a note](/api-reference/leads/add-note) |
| `leads.capture` | Capture leads | Capture leads from a website or form: add a lead or update the existing one with the same phone or email. Cannot read, list or change anything else. | [Capture a lead](/api-reference/leads/capture-lead), [List lead fields](/api-reference/reference/list-fields) |

### Kinds of key

| Kind | Scopes | Expires after | Use it for |
| - | - | - | - |
| Website form | `leads.capture` | 730 days | A website or landing-page form that sends enquiries in as leads. Can do nothing else. |
| Another application | Chosen when created | 90 days | Any other integration. Choose the scopes it needs when you create it. |

## Rotate a key without downtime

1. Create a new key with the same scopes.
2. Switch your server to the new key and deploy.
3. Revoke the old key in **Settings → Connections → API keys**.

## Revoke a key

Revoke a key in **Settings → Connections → API keys**. It stops working on the next request.
