When creating a new client ID and secret it is necessary to list which scopes should be granted to those credentials. In addition, when requesting an access token using a client ID and secret, the list of scopes can be further reduced as compared to the list of scopes of the credentials. It is not possible for an access token to obtain a scope that has not been granted to the client ID and secret.
To reduce the scopes of a token, pass them space-separated in the scope field when requesting an access token, for example "scope": "payable:read settlement:read". Requesting a scope that was not granted to the credentials returns a 401 error.
List of currently supported scopes
| Scope | Description |
|---|---|
payable:read | Allows read-only access to payables, including snapshots of payables |
payable-attachment:read | Allows retrieving documentary evidence (attachments) of payables |
settlement:read | Allows read-only access to settlements |
bank-fee:read | Allows read-only access to bank fees |
wallet-load:read | Allows read-only access to wallet loads |
wallet-summary:read | Allows retrieving the summary of the wallet (balances) |
user:read | Allows retrieving company users (members) |
supplier:read | Allows retrieving the list of suppliers |
cost-center:read | Allows read-only access to cost centers |
cost-center:manage | Allows creating, updating and deleting cost centers |
expense-category:read | Allows read-only access to expense categories |
analytical-field:read | Allows retrieving analytical fields and values |
Experimental scopes
These scopes give access to experimental endpoints, which may change. Request access to experimental features from your CSM or by email at [email protected], then create credentials with the experimental scopes you need.
| Scope | Description |
|---|---|
experimental:accounting-export:read | Allows generating and retrieving file-based purchase and bank journals, their templates and export status |
experimental:accounting-export:write | Used by the Spendesk MCP server; no REST endpoint requires it |
experimental:accounting:update | Allows updating the accounting fields of payables, marking them as ready and updating bookkeeping states |
experimental:chart-of-accounts:read | Allows retrieving accounts and searching creditor account assignments |
experimental:chart-of-accounts:write | Allows creating, updating, syncing and deleting accounts and assigning creditors to them |
experimental:external-reference:read | Allows retrieving external references |
experimental:external-reference:write | Allows creating and updating external references |
experimental:payable-search:read | Allows searching payables |
experimental:payable-attachment:write | Allows uploading attachments to payables |
experimental:invoice:read | Allows listing, summarising and retrieving invoices |
experimental:intake:read | Allows listing and retrieving intakes |
experimental:intake:write | Allows creating intakes and uploading their files |
experimental:purchase-order:read | Allows retrieving purchase orders and their documents |
experimental:purchase-order:write | Allows creating, cancelling and closing purchase orders |
experimental:supplier:manage | Allows creating and updating suppliers and their status |
experimental:card:read | Allows retrieving cards, their order and their blocking history |
experimental:transaction:read | Allows retrieving card transactions |
experimental:request:read | Allows retrieving requests |
experimental:company:read | Allows listing the companies of an organisation (requires an organisation-level token) |
experimental:analytical-field-v2:read | Allows retrieving analytical fields and values (v2) |
experimental:analytical-field-v2:write | Allows creating, updating and deleting analytical fields and values (v2) |
experimental:expense-category-v2:read | Allows retrieving expense category fields and categories (v2) |
experimental:expense-category-v2:write | Allows creating, updating and deleting expense category fields and categories (v2) |
experimental:webhooks:read | Allows retrieving configured web-hooks |
experimental:webhooks:write | Allows configuring web-hooks |