# Access and Permissions

Every API key has an explicit authorization scope. The API evaluates that scope on every REST and MCP request.

## Permission Dimensions

### Dataset Access

A key may allow:

- ICD
- ICDB
- Both datasets

Route visibility does not grant access. The key must be authorized for the requested dataset.

### Record Scope

A key may be limited to an approved subset of records or entities. Filters cannot expand that scope.

### Capability Access

A key may independently allow or deny capabilities such as:

- Structured search and detail retrieval
- Media access
- Geo Manifests
- Natural Language Search
- Domain GenAI
- MCP access

### Usage Controls

Accounts may also have credit, quota, and rate-limit controls. A valid key can still receive a usage-related rejection when a control is reached.

## Privacy-Preserving Responses

For some unavailable, missing, or unauthorized records, the API may use a response that does not confirm whether content exists outside the caller's scope. Integrations must not infer broader dataset contents from empty or not-found responses.

## MCP

MCP tools apply the same dataset, record, feature, quota, and credit controls as the equivalent REST routes. Connecting `/mcp-all` does not override the key's permissions.

## Troubleshooting

- **401 Unauthorized:** the key is missing, invalid, or sent incorrectly.
- **403 Forbidden:** the key lacks a required dataset or capability.
- **404 Not Found:** the identifier is unavailable within the request context, or the route is incorrect.
- **429 Too Many Requests:** wait for the indicated interval and apply backoff.

Contact IntelCenter support if the assigned scope does not match the intended integration.
