> ## Documentation Index
> Fetch the complete documentation index at: https://docs.deal-pipe.de/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication and scopes

> Understand token permissions, organization scope, and revocation.

Send the token as `Authorization: Bearer dp_live_…`. A token belongs to the organization in which it was created; sending an `orgId` does not switch workspaces.

## Effective permissions

For each request, the API intersects token scopes with the creator's current permissions, including configured role changes. The creator's object assignments are applied by the corresponding inventory queries.

| Action | Scope |
| - | - |
| Read projects | `project:read` |
| Create a project | `project:create` |
| Read properties and import status | `property:read` |
| Create a property | `property:create` |
| Import properties | `property:import` |
| Read folders | `files:read` |
| Create folders | `files:upload` |

`GET /projects/{id}?include=properties` requires both `project:read` and `property:read`. Object-scoped tokens cannot create new projects.

## Lifecycle

Keep tokens out of browser code and public repositories. To rotate one, create a replacement, update the integration, and then revoke the old token.

Expired or revoked tokens stop working. An inactive creator or suspended organization can also prevent requests. Check the returned [error code](/en/developers/errors).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.