Evidence-backed facts
- Linear's GraphQL endpoint supports queries and OAuth read scope, which is always present for an authorized user account. informative
- Mutations require write or narrower scopes such as issues:create or comments:create; admin scope should not be requested unless strictly necessary. informative
- OAuth 2.0 is recommended for integrations and can act as the authorizing user or as an application actor for agents and service accounts; personal API keys are for personal scripts. informative
- A GraphQL HTTP 200 can still contain errors, and authentication does not prove that a mutation succeeded or that its effects were accepted. informative