Skip to main content
The request was authenticated, but it is not allowed. The detail field says why. The most common cause is a token that does not carry a scope the endpoint requires; forbidden is also returned when the vendor x-api-key is missing or invalid, and when the request was blocked at the edge. Not retryable. For a missing scope, request it during authorization (the user or firm administrator may need to re-consent) and obtain a new token. For an API key problem, check the key your integration was issued. If your integration was never granted the scope or key it needs, contact FMG. All error codes and the retry model: Errors.