# forbidden_scope

**HTTP 403 — Insufficient scope**

## When you see it

The credential is valid but was not granted the scope this route needs.

## What to do

Request the scope at authorization time. Note that `tasks:read`/`tasks:write` do NOT imply `sessions:*` or `webhooks:write` — those are granted explicitly.

## The response

Every error is [RFC 9457](https://www.rfc-editor.org/rfc/rfc9457) problem+json:

```json
{
  "type": "https://devs.inittasks.com/errors/forbidden_scope",
  "title": "Insufficient scope",
  "status": 403,
  "detail": "a sentence for a developer; never branch on it",
  "instance": "/todos/8E4F2A1B",
  "request_id": "3f9a1c7e-2b44-4d1e-9c30-5a7e8b2d1f60"
}
```

// Branch on `type`, never on `detail` or on the HTTP status alone — several codes share a status.
