Scopes
A token must hold the scope an operation requires, or the request fails with 403. Every MCP connection also needs the mcp scope; no domain scope grants transport access on its own.
Scope names are shortened below. Send them in full, prefixed with https://api.filemark.ca/ and separated by spaces:
scope=https://api.filemark.ca/clients:read https://api.filemark.ca/mcp| Short scope | Grants |
|---|---|
mcp | MCP transport access. Request this for any MCP client |
tax:compute | List computation targets, read their cell contracts, and run deterministic computations |
clients:read | List or get clients |
entities:read | List or get legal entities |
tax-years:read | List or get tax years |
engagements:read | Search, list, and get engagement metadata, amendment context/history, and the year-supported form catalog |
tax-data:read | Read saved trial-balance and account data; combine with tax:compute for saved-state scenarios |
documents:read | List document metadata |
workpapers:read | List workpaper metadata |
review:read | Get review indicators |