parent: authorization
title: permissions
# Permissions
A representation of the permissions granted to your app by
<%= settings.site_name.capitalize %> and a User.
<%= partial 'partials/toc' %>
## Obtainable Permissions
Each application is assigned the minimum set of permissions required to operate
based on its given description. To expand your application's set of acquirable
permissions shoot a mail at <<%= settings.api_email %>>.
<td>All public resources*</td>
<td><%= link_to t('docs.apiv3.favorites'), '/api/v3/favorites' %></td>
<td><%= link_to t('docs.apiv3.notifications'), '/api/v3/notifications' %></td>
<td><%= link_to 'Publishing Actions Related to SKU Reviews',
anchor: 'retrieve-an-skus-reviews' %></td>
<td><%= link_to 'Authorized User Profile', '/api/v3/user' %></td>
<div class="alert alert-warning" role="alert">
<i class="fa fa-exclamation-triangle"></i>
You always have to specify your desired permissions.
<div class="alert alert-info" role="alert">
<i class="fa fa-info-circle"></i> You may specify desired permissions using the
<a href="/authorization/flows#application-token">
<span class="label label-default">scope</span>
parameter in authorization requests.
## Public Resources
Having obtained the public permission you can access the following resources:
* <%= link_to t('docs.apiv3.category'), '/api/v3/category/' %>
* <%= link_to t('docs.apiv3.sku'), '/api/v3/sku/' %>
* <%= link_to t('docs.apiv3.product'), '/api/v3/product/' %>
* <%= link_to t(''), '/api/v3/shop/' %>
* <%= link_to t('docs.apiv3.manufacturer'), '/api/v3/manufacturer/' %>
* <%= link_to t(''), '/api/v3/search/' %>
* <%= link_to t('docs.apiv3.filter_groups'), '/api/v3/filter_groups/' %>
## User Resources
These permissions require that you have explicitly requested them using
the scope param.
Users consent will be required in order to grant any of those permissions.
You **must not** share these data with 3rd parties.
* <%= link_to t('docs.apiv3.user'), '/api/v3/user/' %>
* <%= link_to t('docs.apiv3.favorites'), '/api/v3/favorites/' %>
* <%= link_to t('docs.apiv3.notifications'), '/api/v3/notifications/' %>