Scopes are permissions that control what an agent key can do. Each tool requires a specific scope, so you can grant an agent exactly as much power as you want — no more. The scopes are:
- read_only — view-only: balances, transaction history, exchange rates, profile, limits, and browsing offers/trades. No money moves.
- transfer — send tokens to other users.
- swap — swap between currencies.
- offers — create/engage/cancel offers and trades (prediction markets).
- fiat — fiat operations (deposits, withdrawals, KYC) — these also require verified KYC.
A read-only key can look but never move funds. Give an agent only the scopes it needs.