Scopes
Permissions are granted at install, verbatim from the manifest's scopes, and shown on the Mozaik-owned consent screen with Turkish labels from the platform scope registry (KVKK-sensitive scopes are highlighted). An extension-attributed action runs with exactly its granted scopes.
| scope | commands it gates |
|---|---|
agents:admin | token.mint, token.revoke, workspace.create, workspace.archive |
catalog:write | catalog.category.create, catalog.category.update, catalog.category.archive, catalog.product.create, catalog.product.update, catalog.product.archive, catalog.price.set, catalog.stock.adjust, catalog.stock.set, catalog.digital.codes.add, catalog.digital.codes.void, catalog.product.setVariants, catalog.product.setMedia, catalog.collection.create, catalog.collection.update, catalog.collection.archive, catalog.collection.setProducts, catalog.media.commit, catalog.media.delete, catalog.product.setDigital, metafield.set, metafield.unset |
checkout | order.return.request, order.return.cancel, customer.identity.attach, order.create |
design:write | design.publish, design.rollback |
orders:write | order.ship, order.shipment.track, order.shipment.cancel, order.cod.collect, order.note.add, order.return.approve, order.return.reject, order.return.receive, order.return.settle, order.line.epin.fulfill, customer.identity.unlink, customer.anonymize, order.transfer.confirm, order.cancel, order.refund.request, order.refund.record |
proposals:approve | proposal.approve, proposal.reject, proposal.item.skip |
proposals:write | proposal.submit, proposal.withdraw |
secrets:write | secret.set, secret.delete |
store:admin | store.syncKv, settings.store.update, settings.identity.update, settings.flag.set, extension.install, extension.uninstall, extension.upgrade, extension.enable, extension.disable, extension.configure, extension.hook.deactivate, settings.checkout.update, metafield.definition.create, metafield.definition.update, metafield.definition.delete |
admin implies every scope. checkout is the shopper-session scope used by the enclave itself.
Generated from the live platform registries at build time โ reference pages cannot go stale. Markdown variant: /reference/scopes.md