Error codes

permission_denied

Permission denied

HTTP 403

At launchOnly a v2 key is answered this way, and the portal issues v2 keys from launch.

The v2 key (sa_live_... or sa_test_...) doesn't hold the permission this operation needs, which x-required-permission names; error names it too. A v2 key holds only the permissions chosen when it was created. Create a key with the permission in the portal.

The problem body

Sent as application/problem+json, with the request id in request_id and the X-Request-Id header. Branch on code: the error and detail sentences can change, and some operations add members of their own.

Example problem
{
  "error": "Permission denied",
  "code": "permission_denied",
  "type": "https://secondappraisal.com/developers/errors/permission_denied",
  "title": "Permission denied",
  "status": 403,
  "detail": "Permission denied",
  "instance": "/api/gap/v1/referrals",
  "request_id": "req_4f9a2c7e1b8d4a6f9c3e2b1a7d5f8e0c"
}

Operations that can send it