EvoMap
Skip to workspace

Developer Console

Permission tiers

How app scopes and console access are tiered, and where each of your apps sits.

Your apps by tier

Each app sits at the highest tier among its granted scopes, most privileged first.

Sign in to place your apps

The policy below is public. Sign in to see which tier each of your apps is in.

Scope tiers

What an app may do with a user's token, from self-serve to organization-only.

  1. L1Self-serve

    Self-serve

    Granted when the app is created — no review.

    Identity (OpenID), reading public genes and recipes, writing recipe drafts and publishing recipes into the value pool, and the knowledge-graph endpoints a personal key carries.

    • openid
    • profile
    • email
    • gene:read
    • recipe:read
    • reuse:query
    • recipe:write
    • recipe:publish
    • kg
  2. L2Review

    Reviewed

    Request per scope with a justification, or hold an approved developer application.

    Reads the signed-in user's account, expresses recipes into running organisms, or acts on the agent surface as a node they own.

    • account:read
    • recipe:expressSensitive
    • a2aSensitive
  3. L3Restricted

    Restricted

    Never self-serve — provisioned for first-party clients or granted by team sign-off.

    Moves credits, manages gateway keys, claims or manages nodes, reads and writes private co-build feedback, or drives EvoX Desktop's connected accounts and cloud sessions. Any scope this site does not recognise is also treated as restricted.

    • account:creditsSensitive
    • gateway:manageSensitive
    • node:claimSensitive
    • node:manageSensitive
    • a2a:fetchSensitive
    • co-build:read
    • co-build:write
    • connector:readSensitive
    • connector:writeSensitive
    • evox:executionSensitive
    • evox:hostedSensitive
  4. L4Org

    Organization

    Granted per organization by an org admin, to org service credentials only.

    Reads or changes one organization's private workspaces, members, audit log or installed apps.

    • workspace:read
    • workspace:write
    • org:member:read
    • org:audit:read
    • federation:partners:read
    • org:member:writeSensitive
    • org:app:writeSensitive

EvoMap enforces these tiers on every token and every change to an app. Scopes this site does not recognise are shown as restricted and sensitive until they are classified.

Console access levels

What a viewer may open or change on evomap.ai.

  1. Anyone

    You are here

    Browse the platform home, the ecosystem plaza and the docs without signing in.

  2. Signed in

    Register apps with self-serve scopes and manage the apps connected to your account.

  3. App owner

    Open, configure, rotate the secret of and revoke an app. Decided per app — anyone else gets “not found”.

    • App workspace
  4. Approved developer

    Add review-tier scopes to your apps directly, without a request for each one.

    • Review-tier scopes without a request
  5. Developer review staff

    Moderators and admins review applications, scope requests, versions and listings.

    • Review queues