API reference

Error code: insufficient_scope

insufficient_scope returns HTTP 403 with type: authentication_error. The token lacks the required scope. Branch on this code — it is stable — and apply the fix below.

2 min read

403HTTP status
insufficient_scopeerror.code
FixHandling

What triggers it

The token lacks the required scope. A valid token whose granted scopes do not cover this action.

Example response

{
  "error": {
    "type": "authentication_error",
    "code": "insufficient_scope",
    "message": "The token lacks the required scope."
  }
}

How to fix it

Request a token with the needed scope from the partner console.

This is deterministic: the same request will fail again until fixed. See the HTTP 403 page for the class.

In practice

In a well-built client, insufficient_scope is handled by branching on error.code rather than on the human error.message, which may be reworded over time. The HTTP status (403) gives the broad authentication_error class; the code gives the specifics; and, on field errors, error.param pinpoints the input to fix.

This code is deterministic — retrying the identical request reproduces it — so keep it out of your retry path and instead map it to a clear, actionable message. See Map errors to user-facing messages and Read the error envelope for the pattern.

Frequently asked questions

Is insufficient_scope safe to retry?

No. It is deterministic; retrying the identical request produces the identical error. Fix the cause first.

Will this code ever change?

No. Error codes are stable contract. The human message may be reworded, but the code you branch on will not change.

Do I branch on the code or the HTTP status?

Both — the status for the retry-or-not decision, the code for the specific behaviour. See the error envelope.

Funding for UK limited companies

Credicorp lends to your company, not to you personally — short-term working capital with no personal guarantee. See what your business could access.