> ## Documentation Index
> Fetch the complete documentation index at: https://docs.primevault.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Permissions for API User

> Compare the Admin and User roles for PrimeVault API users, including vault access and creation rights, and follow least-privilege best practices.

Every PrimeVault API user is assigned a role that controls what it can access and do within your organization. Choose **Admin** or **User** when you create the API user.

## Roles for API users

<CardGroup cols={2}>
  <Card title="Admin" icon="user-shield">
    * Has read access to all vaults within the org by default.
    * Can create vaults and manage contacts.
  </Card>

  <Card title="User" icon="user">
    * Must be assigned to one or more vaults as a signer or viewer.
    * Cannot create vaults directly.
    * Ideal team members with specific operational roles.
  </Card>
</CardGroup>

## Best practices

* Always assign the minimum privileges each API user needs.

* Regularly review and update policy templates to align with org changes.

<Tip>
  For most integrations, start with a User role assigned to only the vaults it needs, then expand access if required.
</Tip>

## Related

<CardGroup cols={2}>
  <Card title="Testing setup" icon="flask" href="/getting-started/api-user-testing">
    Create a dedicated test API user.
  </Card>

  <Card title="Production setup" icon="rocket" href="/getting-started/api-user-production">
    Create and activate a production API user.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.