Skip to content

Insufficient scope

HTTP 403insufficient_scope

When the API answers 403 insufficient_scope, and how to fix it.

Version v1.1, updated

The type field of every insufficient_scope response links to this page.

On this page

The key is valid, but it lacks a scope the operation needs. required_scopes in the answer lists the scopes of the operation.

At a glance

  • Status: 403 Forbidden

  • Code: insufficient_scope

  • Retry: No. Fix the cause first: the same request gets the same answer.

Causes and fixes

Likely cause

How to fix it

The key was created without that scope.

Create a key with every scope the system needs, switch the system to it, then revoke the old key.

The key has the write scope and the operation reads, or the reverse.

Add the other scope too: a write scope does not include the read scope. See Scopes.

An order creates its customer on the fly.

The key needs customers:write as well as orders:write.

Example

403 insufficient_scopeJSON
{
  "code": "insufficient_scope",
  "detail": "The API key does not have the scopes this operation requires.",
  "instance": "/v1/categories",
  "request_id": "a1b2c3d4-0000-4000-8000-0000000000ee",
  "required_scopes": [
    "products:read"
  ],
  "status": 403,
  "title": "Insufficient scope",
  "type": "https://birp.io/developers/errors/insufficient_scope"
}
  • scopes
  • first-key
  • errors-overview