# One key per agent, only the access it needs

Agent API keys are how your own tools prove who they are to COD PRO. You create a key in the app, pick its scopes, copy it once, and every request it makes is limited to those scopes and to your store.

- Created in: COD PRO, under agent settings
- Scopes: read:orders, read:customers, read:stats, read:wallet, read:configuration, send:otp, write:orders, write:configuration, control:pause
- Visibility: Usage and activity log per key
- Off switch: Revoke one key or pause all API access

## Scopes at a glance

| Scope | Lets the agent |
|---|---|
| read:orders | Read orders, their messages and recent events |
| read:customers | Read a customer's order history |
| read:stats | Read confirmation statistics |
| read:wallet | Read wallet balance and usage |
| read:configuration | Read COD PRO settings |
| send:otp | Send order confirmations (uses wallet credit) |
| write:orders | Confirm or cancel orders and release holds |
| write:configuration | Change COD PRO settings |
| control:pause | Pause or resume COD PRO |

Next: [make your first call](/developers/api-quickstart).

## FAQ

### Which scopes should I give a reporting agent?
Read scopes only, for example read:orders, read:stats and read:wallet. A read-only key can look but cannot change or send anything.

### Can a key send messages that cost money?
Only if you grant send:otp. Those sends use your wallet at normal prices and have their own per-minute limit.

### Can I see what my agent has been doing?
Yes. COD PRO keeps a usage and activity log for each key, and it never stores a shopper's raw phone number or email from a lookup.

### What if a key leaks?
Revoke it in COD PRO and it stops working immediately. You can also pause all API access with one switch while you investigate.

Last updated: 2026-09-26

Canonical: https://codpro.app/developers/agent-keys
