Read-only user to monitor sync status

I created a very small bootstrap frontend that uses the need, completion and scan api. It looks like this: image I will look into the code and see if I could add a second api key which would allow only those (and maybe a bit more?) api calls.