Skip to content

Ironfang Finance API problem type

insufficient_scope

Insufficient scope. HTTP 403.

What it means

The key is valid but does not carry the scope the operation needs, or it belongs to a different organisation from the one the request names.

What to do

Mint a key with the scope the operation documents, for example finance:einvoices:write to validate or generate, and use it for its own organisation.

What the response carries

type
https://ironfang.uk/problems/insufficient_scope, this page.
status
Always 403 for this code.
code
insufficient_scope. Stable: branch on this, not on the wording of title or detail.
detail
What happened this time, safe to show to a person. It never carries invoice content.
request_id
The same value as the X-Ironfang-Request-ID header. Quote it to support.
retry_after_seconds
Never present for this code.
outcome
Absent. This code is not a statement about any document.

Problems follow RFC 9457 and are served as application/problem+json. A validation finding is never a Problem: an invalid invoice is a successful response that lists its findings. See every problem type, the Finance guide and the OpenAPI contract.