Discover Apple Ads orgs
Live GET /acls against Apple: every org the stored credential reaches, flagging which are already imported and which are read-only. A read-only org (no API Account Manager role) can be imported and read, but every write will fail — the flag is the warning. POST because it burns Apple's quota; it sits in the strictest rate-limit bucket.
Required scope: admin.
Authorization
bearerAuth An API key from Workspace → Settings → API keys, sent as Authorization: Bearer tsk_….
Authorization has two independent axes.
The scope is ranked — a key satisfies any requirement at or below its own tier:
read— see state. Never changes anything.write— propose changes (theactions/*endpoints), trigger audits and reports.admin— connection, account import, sync, targets and brief.
There is no approve scope. It was a rung once; it is not one now, and a key requested with it is rejected.
The approval grant (can_approve) is a separate boolean, not a rung. Deciding a queued proposal — approve, reject, revert — needs write and the grant. Keeping them on separate axes is what makes the review gate a control rather than a convention: a key that may propose is not automatically a key that may approve its own proposal.
A key is either org-scoped (reaches every account, optionally limited to a subset) or bound to a single account.
In: header
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/api/v1/connection/discover"{ "orgs": [ { "asaOrgId": "string", "orgName": "string", "imported": true, "roleNames": [ "string" ], "warning": "string" } ]}