Skip to main content
A 403 means the token may be valid, but this partner or provider cannot run that call. That is different from a 401, where Login failed or sdp_suki_token is missing or expired. Read the error id before you rotate credentials. Patient Summary also returns permission_denied when the partner cannot access the summary organization on Get, PreVisit, or Status. Form filling APIs use the same ids for these cases.

Common causes

  • The Suki Token is valid, but the organization or resource is not available to your partner.
  • The method needs sdp.write and your partner config does not allow it.
  • SBAC blocks an organization that is not linked to your partner account.
  • You refreshed Login for a 403 that was really an organization or scope problem.

Fix

1

Check for 401 First

If the error is invalid_sdp_token or Login failed, follow 401 Unauthorized or invalid Partner Token.
2

Read the 403 Error Id

Match permission_denied, insufficient_scope, or sbac_denied in the response message (exact match or prefix).
3

Fix insufficient_scope

Confirm your partner account allows sdp.write for the method you called. Ask your Suki partnership team if write scope is missing.
4

Fix permission_denied or sbac_denied

Confirm the organization, encounter, or summary ids belong to an organization your partner can access. For Patient Summary, confirm the summary organization is linked to your partner account.
Staging credentials against production hosts (or the reverse) can look like auth failures. See Wrong staging vs production endpoints.

Next steps

Ambient and Dictation error messages - Auth and authorization error ids Form filling error messages - Form filling permission_denied and related ids Patient Summary error messages - Summary organization SBAC failures 401 Unauthorized or invalid Partner Token - Partner Token and invalid_sdp_token failures Partner authentication - Token exchange and partner setup
Last modified on September 29, 2026