Scopes

Scopes limit what a token may do. You choose which scopes your app is allowed to use when you create it, and request a subset of them in the scope parameter of the authorize URL.

Scope Grants Plan
profile.read The user's public profile, username and services. Default when no scope is requested. Free
availability.read The user's free time slots. Free
bookings.read The user's existing bookings. Pro
invites.read The user's single-use links. Free
invites.write Create and delete single-use links. Free

Plans

Building on Tikk is free: developer accounts, apps and sandbox testing cost nothing. What your app can do depends on the plan of the Tikk user who connects it, not on you.

  • Free scopes work for every Tikk user.
  • Pro scopes can be requested and approved by every user, and the consent screen labels them as Pro. They only work while that user is on Tikk Pro. Calls from a Free account return 403 with "error": "plan_required", so you can show an upgrade prompt linking to upgrade_url:
{
  "message": "This endpoint requires the Tikk account to be on the Pro plan.",
  "error": "plan_required",
  "required_plan": "pro",
  "upgrade_url": "https://app.tikk.chat/billing"
}

Nothing needs to be reconnected when the plan changes. After an upgrade the same token works immediately; after a downgrade Pro calls return plan_required again. To adapt your UI up front, call GET /token: it lists your token's scopes with available: true or false. Prefer it over hard-coding which scopes are Pro, so your app keeps working if that changes.

Rules

  • A requested scope your app isn't allowed to use is dropped silently, so the token only receives the scopes that are both requested and allowed.
  • Changing your app's scopes applies to the next authorization. Tokens already issued keep the scopes they were granted; ask users to reconnect if you need more.
  • An endpoint called without the scope it needs returns 403 with the missing scope:
{
  "message": "Missing required scope.",
  "scopes": ["bookings.read"]
}

Ask for as little as you need: users see every requested permission on the consent screen.