How do I make an install read-only?

A key’s reach is bounded by its knowledge base permissions, enforced per folder. Scoping a key to viewer on selected folders makes that install read-only and blind to everything else.

Set the scope on the API Keys page under KB Access. Changing it needs a signed-in session, so a key cannot widen its own reach — or any other key’s.

A node that does not exist and a node you cannot see return the same message, deliberately, so nobody can probe for what exists.

bash
# Grant viewer on the folders it should see, on the API Keys page under KB
# Access. viewer is read-only: search and browse, no writes, and a grant on a
# folder covers everything inside it. The key can read back what it may reach:
curl https://apiv2.senso.ai/api/v1/org/api-keys/$KEY_ID/kb-permissions \
  -H "X-API-Key: $SENSO_API_KEY"

Call it

GET/org/api-keys/{keyId}/kb-permissionsOpen in API reference →What this key can reach.