# API scope for private messages

**URL:** https://meta.discourse.org/t/api-scope-for-private-messages/188856
**Category:** Support
**Created:** [May 2, 2021, 1:49am UTC](https://meta.discourse.org/t/api-scope-for-private-messages/188856 "2021-05-02T01:49:16Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![imc](https://avatars.discourse-cdn.com/v4/letter/i/ed8c4c/32.png) [@imc](https://meta.discourse.org/u/imc)
#### Post date: [May 2, 2021, 1:49am UTC](https://meta.discourse.org/t/api-scope-for-private-messages/188856/1 "2021-05-02T01:49:16Z")

</div>

What’s the API scope that gives permission for  
`https://{defaultHost}/topics/private-messages/{username}.json` ?

Within a separate admin panel of our own, we are trying to show a table of pending support group messages that haven’t been replied to (in Discourse), but without creating an API token with ALL access. The **read** permission doesn’t seem to do it:

 ![image](https://global.discourse-cdn.com/meta/original/3X/7/b/7b387235993a538a98547efcd29b5bc123ba352b.png)
