api_client.scope_not_allowed
The API client lacks the scope of the endpoint (entitlements:read, catalogue:read or usage:write), or its client-credentials token lacks the matching app role (Entitlement.Read.All, Catalogue.Read.All or Usage.Write.All): both are required.
| Code | api_client.scope_not_allowed |
|---|---|
| HTTP status | 403 |
| Category | Forbidden |
| Arguments | None (args is {}) |
Example response
{
"type": "https://docs.test.konsolutelab.uk/errors/api_client.scope_not_allowed",
"title": "…",
"status": 403,
"code": "api_client.scope_not_allowed",
"args": {},
"traceId": "00-4bf92f3577b34da6a3ce929d0e0e4736-00f067aa0ba902b7-01",
"instance": "/api/v1/…"
}Handling it
Branch on code, not on title or the status alone, and log traceId. Codes are stable; new codes may appear, so fall back on the HTTP status for a code you do not know. See Handling errors and the list of codes.