<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>thread Re: Finer grained permissions for API access? in Archived Discussions (Read Only)</title>
    <link>https://community.squareup.com/t5/Archived-Discussions-Read-Only/Finer-grained-permissions-for-API-access/m-p/158108#M97689</link>
    <description>&lt;P&gt;I went ahead and passed this feature request along to our API team &lt;a href="https://community.squareup.com/t5/user/viewprofilepage/user-id/256899"&gt;@prgmr&lt;/a&gt;. Thanks again for sharing your thoughts here.&lt;/P&gt;</description>
    <pubDate>Sun, 22 Mar 2020 16:18:09 GMT</pubDate>
    <dc:creator>nika</dc:creator>
    <dc:date>2020-03-22T16:18:09Z</dc:date>
    <item>
      <title>Finer grained permissions for API access?</title>
      <link>https://community.squareup.com/t5/Archived-Discussions-Read-Only/Finer-grained-permissions-for-API-access/m-p/156571#M97685</link>
      <description>&lt;P&gt;We would like to proactively limit our API access to the information needed to create a transaction in our own billing system.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We really don't want card_details to be accessible to the API, nor do we want it sent in the webhook notifications. We also don't see a need to have access to customer information with the exception of their email address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any possibility of square adding finer grains permissions for application access? It doesn't help us if those permissions are part of the request - it needs to be set by a policy.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 18:03:49 GMT</pubDate>
      <guid>https://community.squareup.com/t5/Archived-Discussions-Read-Only/Finer-grained-permissions-for-API-access/m-p/156571#M97685</guid>
      <dc:creator>prgmr</dc:creator>
      <dc:date>2020-03-13T18:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: Finer grained permissions for API access?</title>
      <link>https://community.squareup.com/t5/Archived-Discussions-Read-Only/Finer-grained-permissions-for-API-access/m-p/156971#M97686</link>
      <description>&lt;P&gt;&lt;a href="https://community.squareup.com/t5/user/viewprofilepage/user-id/256899"&gt;@prgmr&lt;/a&gt; Glad to see your first post in the Community!!!&amp;nbsp;&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;P&gt;I just double checked for an answer to your question, and I'm afraid the restrictions you're looking to set is not possible. You can limit what OAuth permissions an application has, but it will only affect what API endpoints you can call, not the information you receive.&amp;nbsp;&lt;/P&gt;

&lt;P&gt;&lt;BR /&gt;
If you're interested in checking out&amp;nbsp;our OAuth permissions page, &lt;A href="https://developer.squareup.com/docs/oauth-api/square-permissions" target="_blank"&gt;click here&lt;/A&gt;.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 22:06:47 GMT</pubDate>
      <guid>https://community.squareup.com/t5/Archived-Discussions-Read-Only/Finer-grained-permissions-for-API-access/m-p/156971#M97686</guid>
      <dc:creator>JustinC</dc:creator>
      <dc:date>2020-03-16T22:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Finer grained permissions for API access?</title>
      <link>https://community.squareup.com/t5/Archived-Discussions-Read-Only/Finer-grained-permissions-for-API-access/m-p/157872#M97687</link>
      <description>&lt;P&gt;OK. Then how do we officially make a feature request?&lt;/P&gt;</description>
      <pubDate>Sat, 21 Mar 2020 01:34:58 GMT</pubDate>
      <guid>https://community.squareup.com/t5/Archived-Discussions-Read-Only/Finer-grained-permissions-for-API-access/m-p/157872#M97687</guid>
      <dc:creator>prgmr</dc:creator>
      <dc:date>2020-03-21T01:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: Finer grained permissions for API access?</title>
      <link>https://community.squareup.com/t5/Archived-Discussions-Read-Only/Finer-grained-permissions-for-API-access/m-p/157874#M97688</link>
      <description>&lt;P&gt;We want this as part of defense in depth - if we're going to be offloading our credit card processing to square anyway, it makes sense to limit our own access to what we actually need to operate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We'd actually appreciate the same limits on the UI as well, but that is much less likely to happen.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Mar 2020 01:39:42 GMT</pubDate>
      <guid>https://community.squareup.com/t5/Archived-Discussions-Read-Only/Finer-grained-permissions-for-API-access/m-p/157874#M97688</guid>
      <dc:creator>prgmr</dc:creator>
      <dc:date>2020-03-21T01:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Finer grained permissions for API access?</title>
      <link>https://community.squareup.com/t5/Archived-Discussions-Read-Only/Finer-grained-permissions-for-API-access/m-p/158108#M97689</link>
      <description>&lt;P&gt;I went ahead and passed this feature request along to our API team &lt;a href="https://community.squareup.com/t5/user/viewprofilepage/user-id/256899"&gt;@prgmr&lt;/a&gt;. Thanks again for sharing your thoughts here.&lt;/P&gt;</description>
      <pubDate>Sun, 22 Mar 2020 16:18:09 GMT</pubDate>
      <guid>https://community.squareup.com/t5/Archived-Discussions-Read-Only/Finer-grained-permissions-for-API-access/m-p/158108#M97689</guid>
      <dc:creator>nika</dc:creator>
      <dc:date>2020-03-22T16:18:09Z</dc:date>
    </item>
  </channel>
</rss>

