Permission keys
Every Instant Convert permission key, the screen and routes that demand it, what the install grants it from, and the two core pool-backing keys that govern the Instant Convert house page.
A route declares its key in its metadata with requiresAuth. Each admin screen
declares a key in its permission.ts, which builds the frontend's route gate.
That is the same view key as the route the screen reads, except on two
screens: the console's front page declares access.convert while the dashboard
route demands view.convert, and the Settings screen declares
access.convert.settings while its routes demand view.convert.settings and
edit.convert.settings. Super Admin holds every key by name. The grant rules
and the reasoning behind them are in Permissions.
Instant Convert keys
| Key | Demanded by | Granted by the install from |
|---|---|---|
access.convert |
the console's front page (/admin/convert) and its admin menu entry |
view.transaction |
view.convert |
the dashboard (GET /api/admin/convert/dashboard) |
view.transaction |
view.convert.asset |
the Assets screen; GET asset list and one asset |
view.transaction |
edit.convert.asset |
add, edit, delete and bulk-delete assets | edit.deposit + edit.withdraw |
view.convert.order |
the Orders screen; GET order list and one order |
view.transaction |
view.convert.send |
the Sends screen; GET Send list and one Send |
view.transaction |
manage.convert.send |
approve, confirm as sent, cancel on chain, reverse | nobody |
view.convert.inventory |
the Inventory screen; GET house inventory and Send chains |
view.transaction |
edit.convert.inventory |
fund, defund, rescan, floor and target, add, edit and delete Send chain rows | edit.deposit + edit.withdraw |
view.convert.hedge |
the Hedges screen; GET hedge list, one hedge, the per-currency state |
view.transaction |
manage.convert.hedge |
resolve a hedge in review, unfreeze a currency, reopen quoting | nobody |
view.convert.rebalance |
the Movements screen; GET movement list and one movement |
view.transaction |
edit.convert.rebalance |
start a movement by hand | edit.deposit + edit.withdraw |
manage.convert.rebalance |
resolve a movement | nobody |
view.convert.pnl |
the Profit & Loss screen; GET /api/admin/convert/pnl |
view.transaction |
access.convert.settings |
reaching the Settings screen | view.transaction |
view.convert.settings |
GET /api/admin/convert/settings |
view.transaction |
edit.convert.settings |
PUT /api/admin/convert/settings; Sweep now (POST /api/admin/convert/pnl/sweep) |
edit.deposit + edit.withdraw |
Holding edit.convert.settings is not enough for the nine protected settings:
the settings route re-checks the Super Admin role on every save that includes one.
The core house page
The house page (Instant Convert house) is part of the core pool-backing console and uses its keys, not Convert's, so it keeps working when the Convert keys and routes are unreachable.
| Key | Demanded by |
|---|---|
view.pool.backing |
the house page and GET /api/admin/finance/pool-backing/house |
manage.pool.backing |
every house page action: defund, the kill switches, confirm or reverse a Send, resolve a hedge or a movement, and the page's own two-factor endpoints. Always with a fresh second factor; the kill switches also need the Super Admin role |
User routes
The user routes need a signed-in account and no permission key. An API key needs
the trade scope for POST /api/convert/order, and also for
GET /api/convert/order and GET /api/convert/order/{id}: the path prefix is
listed by name among the platform's scoped money routes, the match ignores the
method, and it fails closed without the scope.