Description of problem: Please, add a more limited capability than 'users=read' for admin API requests that don't require access to users' keys.