Permissions Page: Mapping Tools to Vendor API Permissions
The API Permissions planner answers one question: "If I want the AI to use these tools, what permissions does my vendor API key need?" Open Connectors, open the connector's panel, and select API…
Written By Christopher Scaminaci
Last updated 3 days ago
The API Permissions planner answers one question: "If I want the AI to use these tools, what permissions does my vendor API key need?" Open Connectors, open the connector's panel, and select API Permissions. Use it to scope a least-privilege API key or integration account in your PSA/RMM/documentation product before you wire up the connector.
The standalone /permissions route remains available as a deep link. It adds a connector picker and a short guided tour, but it is no longer a portal-navigation item.
Nothing you select on this page is saved or enforced — it is a planning calculator. (To actually restrict which tools a client can call, use the tool selector on the Endpoints page — see Choosing tools for each client.)

How to use it
- Open Connectors, open the connector you are configuring, and select API Permissions. If you entered through the
/permissionsdeep link instead, pick the connector from its dropdown. - The planner loads that connector's full tool catalog, grouped by category (for example Tickets, Companies, Assets).
- Select the tools you expect the AI to use — via presets, whole categories, or individual checkboxes.
- Read the Required Permissions panel on the right. It updates live and lists the deduplicated set of upstream vendor permissions your API key/account needs for the selected tools, with a count.
- Treat the result as a planning baseline: use the copy button to copy the permission list, grant those scopes when creating the API key or integration account, and follow the connector guide for any vendor-specific role, product entitlement, tenant, or resource-access requirement.
The standalone /permissions deep link runs a short guided tour the first time you visit it; you can replay that tour from the page header.
Quick-select presets
Five preset buttons at the top of the tool list make common selections one click:
Why "Read + Write" equals "All Tools"
This is intentional. Read Only is the subset the planner can show are reads (mapped permissions all read-type, or — HaloPSA only — the admin-labelled reads its tool metadata certifies), while Read + Write explicitly selects every tool. It is the "everything, including tools that write" preset; it does not infer that every write tool also carries a separate read permission. Its value is in the Required Permissions panel: it shows the full mapped read, write, administrative, and connector-specific permission set, whereas Read Only shows only the scopes its tools need — for HaloPSA that includes admin, which the panel lists under Write Access because it is the scope you grant, whatever the tool does with it. Compare the two before deciding whether to issue a read-only key or a broader key.
Working with the tool list
- Search filters tools by name or display name across all categories.
- Category groups are collapsible; each has a Select all / Deselect all toggle.
- Every tool shows a plan badge (Free / Pro / Business) so you can see tier requirements while planning — the page lets you select above-plan tools so you can scope a key for a future upgrade.
- Selecting or deselecting any individual tool switches the presets off (your selection becomes custom).
Reading the Required Permissions panel
The right-hand panel is the output. For each selected tool, StackJack knows which vendor API permission strings it needs (for example a Halo permission area, a CIPP role, or an Autotask security-level requirement, depending on the connector). The panel:
- Deduplicates — ten ticket tools that all need the same ticket-read permission produce one line.
- Groups read vs write permissions so you can see at a glance whether your selection stays read-only. The grouping is by scope shape, not by tool: HaloPSA's area-shaped
adminscope always lists under Write Access, even when every selected tool that needs it is a read. - Copies to clipboard in one click for pasting into a change ticket or the vendor's admin UI.
Practical workflow: least-privilege connector setup
- On Connectors, open the connector's API Permissions planner and click Read Only (or hand-pick the tool families you need).
- Copy the permission list and create a vendor API key with those scopes plus any vendor-specific role, product entitlement, tenant, or resource access described in the connector guide.
- Add the key on the Connectors page.
- On Endpoints, restrict your MCP client's tool selection to the same tools, so the AI can't even attempt calls the key would reject.
The result is defense in depth. If the AI tries a tool excluded from the MCP client's selection or above the connector's current plan, StackJack refuses the call before contacting the vendor. For a call StackJack does permit, the vendor still enforces the API key's scopes and the account's own role, product, tenant, and resource access.
More in Tools & Catalog
How MCP Tools Work in StackJackNative Anthropic Tools: Web Search, Web Fetch, and Code ExecutionStackJack Platform Tools (stackjack_*)Response Shaping: Trimming Tool Responses to Save ContextStill need help? Ask the team