Skip to content
FirstSIDocs

Token scopes

What each scope allows.

A token carries one or more scopes. A route or MCP tool refuses the call (403) if its scope is missing. Grant the minimum: a ticketing connector only needs read:machines and read:netdiag, for example.

ScopeGives access to
read:machinesFleet: workstations and servers running the agent.
read:netdiagNetDiag: verdicts, measurements, events and applications of workstations.
read:flowsNetwork flows, destinations, volumes, flow explorer.
read:alertsOpen alerts and incidents.
read:monitorsAvailability: monitors, incidents, probes.
read:inventorySoftware inventory, vulnerabilities, end of life, licences.
read:securitySecurity: SIEM, Active Directory authentications.
read:databasesDatabases: instances, queries, waits, sessions.
read:dnsDNS: queries and threats.
read:filesFile access: events and shares.
read:networkNetwork infrastructure: devices, links, tunnels, Wi-Fi.
read:firewallFirewalls and gateways: logs, traffic, threats.
report:pdfPDF reports (e.g. the NetDiag report of a workstation).
write:alertsWrite: acknowledge an alert (logged with its body).
write:netdiagWrite: NetDiag settings and diagnostic actions (logged).

Source: · FirstSI Docs · updated 2026-10-10