HTTP 403, authentication and identity
AUTH-017
This token lacks the required scope.
What it means
The token is valid but was not granted the scope this endpoint needs.
What to do
Issue a token with the scope named in the endpoint's documentation. Scopes are chosen explicitly at creation; none is preselected.
The response
Every failure arrives in this shape. The trace_id is worth keeping: it identifies the request in our logs and carries nothing about your data.
{
"type": "https://shiftgraph.dev/errors/AUTH-017",
"title": "This token lacks the required scope.",
"status": 403,
"code": "AUTH-017",
"trace_id": "01J8Z…"
}Related codes
Sessions, second factors, sign-in methods, and the credentials that reach the API. A second factor is required of every account, so several of these have no bypass by design.
- AUTH-001Invalid email or password.HTTP 401
- AUTH-002Your session has expired. Sign in again.HTTP 401
- AUTH-003Second factor required.HTTP 401
- AUTH-004That code didn't match. Try again.HTTP 401
- AUTH-005This action needs a fresh verification.HTTP 403
- AUTH-006Too many attempts. Wait before trying again.HTTP 429
- AUTH-007That link is no longer valid.HTTP 400
- AUTH-008Your account is suspended.HTTP 403
- AUTH-009That verification code has expired. Request a new one.HTTP 400
- AUTH-010This sign-in method is already linked.HTTP 409
- AUTH-011Removing this would leave no way to sign in.HTTP 400
- AUTH-012Cross-site request blocked.HTTP 403
- AUTH-013This session was signed out.HTTP 401
- AUTH-014Password does not meet the requirements.HTTP 400
- AUTH-015ShiftGraph is currently invite-only.HTTP 403
- AUTH-016Invalid or revoked API token.HTTP 401
The full error reference, or write to support@shiftgraph.dev with the trace id.