Skip to main content
Each API key has a set of permissions — the checkboxes on the key’s page in the account. SaaS API methods check these permissions: if a required checkbox is not enabled, the API returns 401 with cause: "Forbidden" and the message Forbidden seller resource - permissions <Code>. Only the permissions that SaaS API methods actually check are listed below. The other checkboxes on the key’s page do not affect the API.

Where to enable permissions

1

Open the API keys page

Manage → School → For developers → API keys (/manage/school/api-keys).
2

Open the key settings

In the row of the key you need, select “Edit”.
3

Select checkboxes and save

The checkboxes are grouped into sections: “School Management”, “Course Management” and so on. Click “Save”.
If a method lists several permissions, any one of them is enough.
Exports check permissions not at launch but while the file is being built: without the required permission, query-export/generate still responds with 201, but the export ends with status: Failed.

Permissions by task

Choose what your integration should do and enable the corresponding checkboxes.

Permission reference

In the error text, the API refers to a permission by its technical code, for example Forbidden seller resource - permissions FormManage. Use the code in the right column to find which checkbox to enable.

School Management

Course Management

Forms management

Organization Management

Staff Management

This section exists only in corporate schools.

Default permissions

A new key immediately receives all the permissions that SaaS API methods need for its school type:
  • in any school — “School User Management”, “Forms management”, “Course Curator”, “Course Student Management”, “Course Management” and the other permissions in the “School Management” and “Course Management” sections;
  • in a commercial school — additionally “School Sales” and “School Refunds”;
  • in a corporate school — additionally “Staff Management” and “Staff browsing”.
So a fresh key works with all methods without any setup. Change the checkboxes when you need to restrict the integration: for example, leave a key for employee sync with only the permissions of the “Staff Management” section. If, after such a setup, a method returns 401 Forbidden seller resource - permissions <Code>, find the checkbox it needs in the tables above.

Differences in corporate schools

In corporate schools, some checkboxes are labeled differently: “Company User Management” instead of “School User Management”. The permission code stays the same. The “School Sales” and “School Refunds” checkboxes are not shown in corporate schools.

System permissions

The key’s service user automatically receives the system API client flag (UserIsApiClient) — without it, SaaS methods do not work. It is not shown in the account, and you do not need to configure it. If a request with a valid token returns an access error even though all the required checkboxes are enabled, contact support.
Updated: 2026-09-28 05:04 UTC