policy. To create a scoped key, see Scope a key to specific resources.
Resources
Resources must be inside the new key’s organization, or its project for a project-scoped key. Kernel checks that every object ID exists when you create the key.
Actions
Browsers
Profiles
Vaults
Proxies
Projects and organizations
Operations that need more than one action
List endpoints return only the objects the key can access, so a key without a matching grant gets an empty list.
Not available to scoped keys
Scoped keys get403 with insufficient_scope on:
- API key management, including creating, listing, rotating, and deleting keys.
- Browser pools.
- Creating browsers that use saved extensions, telemetry export, or app invocations.
- Any other endpoint not covered by the actions above.