Narrowed keys stay inside their scopes
A key or agent token limited to specific scopes is now refused on routes that take no scope, and pricing function, routing policy, batch and UCP routes now name the scope they need.
Until now a route that named no scope accepted any credential of the workspace. A key created with only price:compute, or an agent's key, could still register webhooks, create invoices or change workspace settings.
Routes now fail closed. A credential limited to specific scopes (scopes recorded and no *), and any agent credential, gets 403 insufficient_scope on a route that names no scope. A workspace key created without scopes or with *, a person's token without scopes and the dashboard session work as before.
These routes stay open to every key: GET /api/me, the usage reads, compute and price router calls, day passes, prepaid balance and top up, and the API key routes.
These routes now name a scope:
POST /api/compute/batch:price:compute:batch.- Listing and reading pricing functions:
pcn:function:read. Verifying a price:price:compute. - Publishing, editing and deleting a pricing function:
pcn:function:publish. Testing one:pcn:function:test. - Routing policies:
pcn:routing:readto read,pcn:routing:writeto change. - Recording a usage outcome:
price:computeorprice:compute:batch. - Usage signals,
POST /api/price-router/pipelines, the UCP quote and checkout session routes:price:compute.
If a key stops working, create one with the scopes it needs, or one without scopes. For help, write to support@last-price.ai.