Scopes
Scopes limit what a token may do. You choose which scopes your app is allowed to use when you create it, and request a subset of them in the scope parameter of the authorize URL.
| Scope | Grants | Plan |
|---|---|---|
profile.read |
The user's public profile, username and services. Default when no scope is requested. | Free |
availability.read |
The user's free time slots. | Free |
bookings.read |
The user's existing bookings. | Pro |
invites.read |
The user's single-use links. | Free |
invites.write |
Create and delete single-use links. | Free |
Plans
Building on Tikk is free: developer accounts, apps and sandbox testing cost nothing. What your app can do depends on the plan of the Tikk user who connects it, not on you.
- Free scopes work for every Tikk user.
- Pro scopes can be requested and approved by every user, and the consent screen labels them as Pro. They only work while that user is on Tikk Pro. Calls from a Free account return
403with"error": "plan_required", so you can show an upgrade prompt linking toupgrade_url:
{
"message": "This endpoint requires the Tikk account to be on the Pro plan.",
"error": "plan_required",
"required_plan": "pro",
"upgrade_url": "https://app.tikk.chat/billing"
}
Nothing needs to be reconnected when the plan changes. After an upgrade the same token works immediately; after a downgrade Pro calls return plan_required again. To adapt your UI up front, call GET /token: it lists your token's scopes with available: true or false. Prefer it over hard-coding which scopes are Pro, so your app keeps working if that changes.
Rules
- A requested scope your app isn't allowed to use is dropped silently, so the token only receives the scopes that are both requested and allowed.
- Changing your app's scopes applies to the next authorization. Tokens already issued keep the scopes they were granted; ask users to reconnect if you need more.
- An endpoint called without the scope it needs returns
403with the missing scope:
{
"message": "Missing required scope.",
"scopes": ["bookings.read"]
}
Ask for as little as you need: users see every requested permission on the consent screen.