API key scopes
A scoped API key is an API credential for your Airwallex account that grants Read or Write access to the resource areas you select, instead of full account access. Each scope controls which REST endpoints the key can call and which webhook events you can subscribe to when using that key, so you can give each integration only the access it needs.
Scoped API keys are recommended for production integrations because they limit blast radius if a credential is exposed. For guidance on least privilege, migrating off admin keys, IP whitelisting, and key storage, see API key best practices.
The tables below list every scope available when you create or edit a key. Use them to plan integrations, document access for your team, or look up what a scope enables when you configure keys in the Airwallex web app .
Scopes reference
Scopes are grouped by product. For each scope, the table shows its label, authorized REST operations for Read and Write access, and webhook events. A dash means no APIs or events apply for that column.
Account Capabilities
Billing
Core Resources
Finance
Issuing
Payment Acceptance
Payouts
Risk
| Resource | Read | Write | Webhook events |
|---|---|---|---|
| Request for Information (RFI) |
Connected Accounts
Simulations
| Resource | Read | Write | Webhook events |
|---|---|---|---|
| Simulations | - | Accounts API | - |
Spend
Supporting Services
| Resource | Read | Write | Webhook events |
|---|---|---|---|
| Upload Files | - | Upload a file API | - |