---
title: Access
description: What access and credential mean on a catalog row, and how to tell a runnable endpoint from one that needs your own account or has no key yet.
---

Every catalog row carries `access`, and most rows also carry `credential`. Together they say
whether you can run a row right now, and whose key it runs on.

## `access`

| Value | Meaning |
| --- | --- |
| `runs_now` | Keyless, or a platform key already exists. Call it now. |
| `needs_your_account` | The endpoint acts on your own account with the provider (an Instantly, Gmail, LinkedIn or Meta Ads style integration). Connect your account first with `POST /v1/connections`. |
| `coming_soon` | A registered provider with no platform key yet. Do not pick this row; it has no key to run on. |

## `credential`

`credential` says whose key a run actually uses:

| Value | Meaning |
| --- | --- |
| `none` | Keyless call. |
| `yours` | Runs on this workspace's own connected key. |
| `platform` | Runs on looot's platform key. |
| `platform_own_key_optional` | The platform key can run it; connecting your own key is optional. |
| `own_key_required` | Needs your own key; there is no platform key for it. |
| `unavailable` | Prohibited, or not eligible for your own key and no platform key exists. |

`eligibility: "byok"` means a customer key is allowed on that endpoint; it does not by itself say
whether one is required.

## Worked example

Search `job:company.enrich` and you might see:

```json
{ "endpointId": "clearbit-company", "access": "runs_now", "credential": "platform" }
```

That runs immediately on looot's own key. A row with `access: "coming_soon"` returns a
[`provider_error`](/errors/run-errors#provider_error) if you try it anyway; skip it. A row with `access: "needs_your_account"` needs a
connection first, or the run fails with a credential error naming what is missing.

<Related />
