# Feature request: Allow safe API access to site settings without an admin-level key

**URL:** <https://meta.discourse.org/t/feature-request-allow-safe-api-access-to-site-settings-without-an-admin-level-key/408523>\
**Category:** Feature\
**Tags:** rest-api\
**Created:** [July 25, 2026, 11:03pm UTC](https://meta.discourse.org/t/feature-request-allow-safe-api-access-to-site-settings-without-an-admin-level-key/408523 "2026-07-25T23:03:41Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)\
**Post date:** [July 26, 2026, 9:34am UTC](https://meta.discourse.org/t/feature-request-allow-safe-api-access-to-site-settings-without-an-admin-level-key/408523/3 "2026-07-26T09:34:25Z")

</div>

Could you be more specific on which exact site settings?

Unfettered read only access to all site settings seems a bit of a blunt instrument and would include some very sensitive ones including saas keys.

You could build a plugin with group read only access to specific named set of site settings?

That would be a relatively small plugin.

---

_[View the full topic](https://meta.discourse.org/t/feature-request-allow-safe-api-access-to-site-settings-without-an-admin-level-key/408523)._
