MMashDiv

Permission keys

Every Instant Convert permission key, the screen and routes that demand it, what the install grants it from, and the two core pool-backing keys that govern the Instant Convert house page.

1 min readUpdated 28 September 2026reference, permissions, roles, routes

A route declares its key in its metadata with requiresAuth. Each admin screen declares a key in its permission.ts, which builds the frontend's route gate. That is the same view key as the route the screen reads, except on two screens: the console's front page declares access.convert while the dashboard route demands view.convert, and the Settings screen declares access.convert.settings while its routes demand view.convert.settings and edit.convert.settings. Super Admin holds every key by name. The grant rules and the reasoning behind them are in Permissions.

Instant Convert keys

Key Demanded by Granted by the install from
access.convert the console's front page (/admin/convert) and its admin menu entry view.transaction
view.convert the dashboard (GET /api/admin/convert/dashboard) view.transaction
view.convert.asset the Assets screen; GET asset list and one asset view.transaction
edit.convert.asset add, edit, delete and bulk-delete assets edit.deposit + edit.withdraw
view.convert.order the Orders screen; GET order list and one order view.transaction
view.convert.send the Sends screen; GET Send list and one Send view.transaction
manage.convert.send approve, confirm as sent, cancel on chain, reverse nobody
view.convert.inventory the Inventory screen; GET house inventory and Send chains view.transaction
edit.convert.inventory fund, defund, rescan, floor and target, add, edit and delete Send chain rows edit.deposit + edit.withdraw
view.convert.hedge the Hedges screen; GET hedge list, one hedge, the per-currency state view.transaction
manage.convert.hedge resolve a hedge in review, unfreeze a currency, reopen quoting nobody
view.convert.rebalance the Movements screen; GET movement list and one movement view.transaction
edit.convert.rebalance start a movement by hand edit.deposit + edit.withdraw
manage.convert.rebalance resolve a movement nobody
view.convert.pnl the Profit & Loss screen; GET /api/admin/convert/pnl view.transaction
access.convert.settings reaching the Settings screen view.transaction
view.convert.settings GET /api/admin/convert/settings view.transaction
edit.convert.settings PUT /api/admin/convert/settings; Sweep now (POST /api/admin/convert/pnl/sweep) edit.deposit + edit.withdraw

Holding edit.convert.settings is not enough for the nine protected settings: the settings route re-checks the Super Admin role on every save that includes one.

The core house page

The house page (Instant Convert house) is part of the core pool-backing console and uses its keys, not Convert's, so it keeps working when the Convert keys and routes are unreachable.

Key Demanded by
view.pool.backing the house page and GET /api/admin/finance/pool-backing/house
manage.pool.backing every house page action: defund, the kill switches, confirm or reverse a Send, resolve a hedge or a movement, and the page's own two-factor endpoints. Always with a fresh second factor; the kill switches also need the Super Admin role

User routes

The user routes need a signed-in account and no permission key. An API key needs the trade scope for POST /api/convert/order, and also for GET /api/convert/order and GET /api/convert/order/{id}: the path prefix is listed by name among the platform's scoped money routes, the match ignores the method, and it fails closed without the scope.