> ## Documentation Index
> Fetch the complete documentation index at: https://developer.suki.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# 403 Permission Denied, Insufficient Scope, or SBAC Denied

> Fix permission_denied, insufficient_scope, and sbac_denied on Partner API calls

A **403** means the token may be valid, but this partner or provider cannot run that call. That is different from a **401**, where Login failed or `sdp_suki_token` is missing or expired. Read the error id before you rotate credentials.

| Error id | HTTP | Meaning |
| :- | :- | :- |
| `permission_denied` | 403 | General authorization failure |
| `insufficient_scope` | 403 | Method not allowed. Needs `sdp.write` |
| `sbac_denied` | 403 | Organization not accessible to this partner (SBAC) |

Patient Summary also returns `permission_denied` when the partner cannot access the summary organization on Get, PreVisit, or Status. Form filling APIs use the same ids for these cases.

## Common causes

* The Suki Token is valid, but the organization or resource is not available to your partner.
* The method needs `sdp.write` and your partner config does not allow it.
* SBAC blocks an organization that is not linked to your partner account.
* You refreshed Login for a 403 that was really an organization or scope problem.

## Fix

<Steps>
  <Step title="Check for 401 First">
    If the error is `invalid_sdp_token` or Login failed, follow [401 Unauthorized or invalid Partner Token](/documentation/troubleshooting/invalid-partner-token-401).
  </Step>

  <Step title="Read the 403 Error Id">
    Match `permission_denied`, `insufficient_scope`, or `sbac_denied` in the response message (exact match or prefix).
  </Step>

  <Step title="Fix insufficient_scope">
    Confirm your partner account allows `sdp.write` for the method you called. Ask your Suki partnership team if write scope is missing.
  </Step>

  <Step title="Fix permission_denied or sbac_denied">
    Confirm the organization, encounter, or summary ids belong to an organization your partner can access. For Patient Summary, confirm the summary organization is linked to your partner account.
  </Step>
</Steps>

<Tip>
  Staging credentials against production hosts (or the reverse) can look like auth failures. See [Wrong staging vs production endpoints](/documentation/troubleshooting/wrong-environment-endpoints).
</Tip>

## Next steps

<Icon icon="file-lines" iconType="solid" /> **[Ambient and Dictation error messages](/api-reference/error-messages)** - Auth and authorization error ids

<Icon icon="file-lines" iconType="solid" /> **[Form filling error messages](/form-filling-api-reference/error-messages-form-filling)** - Form filling `permission_denied` and related ids

<Icon icon="file-lines" iconType="solid" /> **[Patient Summary error messages](/patient-summary-api-reference/error-messages-patient-summary)** - Summary organization SBAC failures

<Icon icon="file-lines" iconType="solid" /> **[401 Unauthorized or invalid Partner Token](/documentation/troubleshooting/invalid-partner-token-401)** - Partner Token and `invalid_sdp_token` failures

<Icon icon="file-lines" iconType="solid" /> **[Partner authentication](/documentation/how-to/partner-authentication)** - Token exchange and partner setup
