The credential is valid but is not allowed to do this. Two codes answer
with this status, and error.code says which.
insufficient_scope: it does not hold the permission. The
operation needs, say, audience: read on the newsletter addressed, and
this credential holds less than that there. allowed_values carries
the permission that was needed, and the message says what the
credential does hold on that newsletter, because a credential granted
the wrong family and a credential belonging to somebody whose standing
on the team has narrowed look identical without it. The answer can
differ per newsletter: the same credential may be allowed here and
refused on the next one it reaches.
The same code answers an operation that needs the account
permission from a credential that does not carry it. That permission
is about the person a credential belongs to rather than about any
newsletter, so nothing granted on a newsletter adds up to it. It is
granted on the credential itself, when a key is minted or when an
authorization asks for account:read.
And it answers a parameter the credential may send, but not with the
value it sent: a filter a credential holding only read permissions
may not use, or an expand path whose rows need a permission the
operation does not. param names the parameter, and allowed_values
carries what this credential may send instead, or is absent when it may
send nothing there at all.
forbidden: it may not act here at all. Either the credential does
not reach the newsletter addressed, because it was never granted it or
because the person it belongs to can no longer act on it, or it reaches
no newsletter at all; param is newsletter, and GET /newsletters
lists the ones it does reach. Or, on DELETE /api-keys/{key}, the
credential named belongs to somebody else. Neither carries
allowed_values, because there is no value to send instead.