# Which PAT scopes should you grant for each automation job? > Grant the fewest scopes a job needs. A release announcer needs posts:schedule; a draft importer needs drafts:write; a reporting script needs posts:read. Avoid the * wildcard, which grants everything, & add posts:publish only when immediate publishing is truly required. Updated: 2026-10-05. ## The scope list A PAT carries a list of scopes, & each one unlocks a specific group of routes. | Scope | What it allows | |-------|----------------| | `workspace:read` | Read the workspace & its members | | `posts:read` | List & get posts | | `posts:schedule` | Schedule posts & threads | | `posts:publish` | Publish now | | `posts:delete` | Cancel or delete posts | | `drafts:write` | Create, update & delete drafts | | `media:read` / `media:write` | Read the gallery / upload to it | | `memory:read` / `memory:write` | Read / write memories & collections | The SDK also uses `workspace:write` for changing the workspace AI voice. Using `*` grants every scope, & leaving the list empty falls back to a small CI default set. ## Why the minimum matters A token with only `posts:schedule` can queue posts for later but can't publish one this second. If that token leaks, the damage is limited, & a person can still cancel what it queued from the calendar. Each extra scope widens what a leaked token can do. Granting `*` for convenience removes that safety. ## A release announcer Posts a message when you ship. It needs `posts:schedule`, plus `workspace:read` if it lists accounts first, & `media:write` only if it attaches an image. Scheduling a few minutes ahead, instead of publishing, gives a person a window to edit or cancel. ## A draft importer Takes ideas from another system & saves them for a person to finish. It needs only `drafts:write`. Drafts never publish on their own, so this is the safest posting-adjacent scope. DunSocial's draft state is what makes this safe: a person finishes & schedules each idea in the app. ## A reporting script Reads posts to build a report. It needs `posts:read` & `workspace:read`, & nothing that writes. DunSocial's analytics dashboard covers X, Bluesky & Pinterest, so a script like this is a way to pull the post history that the dashboard doesn't summarise for other networks. ## What a PAT can never have No scope lets a PAT call AI routes, manage webhook endpoints, read notifications, touch billing or manage other tokens. Those stay session-only. DunSocial also scopes a PAT to one workspace, so a token for a client workspace can't touch your own. ## Review them like keys Set an expiry when you create a token & note what each one is for in its name. Revoke any token that isn't used. If a job's needs change, create a new token with the right scopes instead of widening an old one. DunSocial lists every token under Settings → CLI, so an audit takes a minute. ## Related guides - [How to authenticate with the DunSocial API](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/how-to-authenticate-with-the-dunsocial-api.md) - [How to run the DunSocial CLI in GitHub Actions](https://www.dunsocial.com/hub/dunsocial-cli-guides/how-to-run-the-dunsocial-cli-in-github-actions.md) - [What permissions does a DunSocial MCP connection need?](https://www.dunsocial.com/hub/dunsocial-mcp-guides/what-permissions-does-a-dunsocial-mcp-connection-need.md) - [How to connect an AI agent to your social accounts safely](https://www.dunsocial.com/hub/social-media-automation-for-developers/how-to-connect-an-ai-agent-to-your-social-media-accounts-safely.md) ## About this document This is the Markdown representation of https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/which-pat-scopes-should-you-grant-for-each-automation-job. The HTML version of the same page is at the same URL. You can also request Markdown from any page by sending `Accept: text/markdown`. Machine-readable summary of the whole site: https://www.dunsocial.com/llms.txt ## Company - Product: DunSocial, https://www.dunsocial.com - Legal entity: THISUX PRIVATE LIMITED, Chennai, Tamil Nadu, India - Support: support@dunsocial.com - Open the app: https://app.dunsocial.com/login