Permissions
Assign least-privilege access using the exact permissions available in Daily.
Select at least one available permission when creating a key. The API checks the exact permission required by each documented operation after authentication, subscription, and IP restrictions. A missing permission returns 403 insufficient_permission.
| Product label (exact) | Permission | Protected endpoints | Purpose |
|---|---|---|---|
| פרטי העסק | business:read | GET /business | Business identity, contact details, and basic configuration. |
| לקוחות | customers:read | GET /customers, GET /customers/{id} | Customer records and their saved contact data. |
| ספקים | suppliers:read | GET /suppliers, GET /suppliers/{id} | Supplier records and their saved contact data. |
| לידים | leads:read | GET /leads, GET /leads/{id} | Leads, contact data, status, and assigned owner summary. |
| מוצרים ושירותים | products:read | GET /products, GET /products/{id} | Products, raw materials, prices, and catalog metadata. |
| מסמכים | documents:read | GET /documents, GET /documents/{id}, GET /documents/{id}/pdf | Documents, line items, relationships, and available PDFs. |
| תשלומים | payments:read | GET /payments, GET /payments/{id} | Recorded payments and document relationships, without sensitive payment details. |
| מלאי | inventory:read | GET /inventory, GET /inventory/movements | Inventory levels and inventory movements. |
| משימות | tasks:read | GET /tasks, GET /tasks/{id} | Tasks, dates, statuses, and linked business objects. |
Existing read permissions are preserved. New write permissions require explicit consent; existing keys do not gain them automatically.
Least privilege
Create a separate key per integration and enable only the rows it needs. This limits exposure, makes usage visible by key, and lets you rotate or revoke one integration without interrupting another.
Permissions can be edited later in Daily. Removing a permission takes effect on subsequent requests; no new key is required.
Missing-permission response
{
"error": {
"type": "authorization_error",
"code": "insufficient_permission",
"message": "This API key cannot access customers."
},
"request_id": "req_docspermissions01"
}Treat this response as configuration failure. Do not retry it automatically; ask the primary business owner to review the key's permissions.
Additional permissions
| Permission | Operation |
|---|---|
customers:write | Manage the customer lifecycle |
suppliers:write | Manage the supplier lifecycle |
leads:write | Manage the lead lifecycle |
products:write | Manage product and raw material lifecycles |
documents:write | Manage document and draft lifecycles |
tasks:write | Manage the task lifecycle |
inventory:write | Manage inventory |
expenses:write | Manage expense, category, and payment lifecycles |
tags:write | Manage the tag lifecycle |
expenses:read | Read expenses, categories, and payments |
tags:read | Read tags |
business:read also covers agent lists and bank account IDs. products:read covers raw materials. documents:read covers drafts. See permissions for combined operations.

