# API Key Permissions

**URL:** <https://community.fibery.io/t/api-key-permissions/4504>\
**Category:** API & Programming\
**Created:** [May 24, 2023, 10:50pm UTC](https://community.fibery.io/t/api-key-permissions/4504 "2023-05-24T22:50:17Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![cannibalflea](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/cannibalflea/32/318_2.png) [@cannibalflea](https://community.fibery.io/u/cannibalflea)\
**Post date:** [May 24, 2023, 10:50pm UTC](https://community.fibery.io/t/api-key-permissions/4504/1 "2023-05-24T22:50:17Z")

</div>

I was wondering if there are any plans to allow admins to limit the scope of API actions that can be performed through a particular API key. I was thinking it might be helpful to be able to create a key that only allows fetching and even possibly limit queries or mutations to a particular space. I think I have seen a discussion on this elsewhere but somehow couldn’t find it.

---

<div class="post-metadata">

**Author:** ![Chr1sG](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/chr1sg/32/3941_2.png) [@Chr1sG](https://community.fibery.io/u/Chr1sG)\
**Post date:** [May 25, 2023, 11:38am UTC](https://community.fibery.io/t/api-key-permissions/4504/2 "2023-05-25T11:38:31Z")

</div>

API keys are basically tied to a user account, so the permissions for the key match the permissions for the user.  
If you create a user with read-only permissions for a specific space, then the API key(s) for that user will be limited to read-only operations for that space.
