Skip to main content

not-entitled

HTTP status: 403 Forbidden Type URI: https://docs.evinor.ai/problems/not-entitled

The API key carries the scope the endpoint requires, but the account that owns the key is not entitled to the operation. Evinor re-checks the owner's entitlement on every call, so a key keeps working only while its owner keeps the entitlement.

This is different from missing-scope: that one is fixed by minting a key with the right scope, this one is fixed on the account.

The body carries a code member naming the check that failed: FORBIDDEN (filing as yourself), GRANT_FORBIDDEN (filing under any grant), or GRANT_NOT_USABLE (this particular grant_id). See Reporting events.

Common causes​

  • Submitting a report (POST /v1/reports) from an account that does not have structured reporting enabled, or no longer has it.
  • Submitting under a grant_id the account cannot use — a grant that does not exist, was issued to someone else, was revoked, has expired, or is for a different event type. The response deliberately does not say which.
  • Submitting under a grant_id from an account without the reporting-grant entitlement.

How to resolve​

Check the account's plan and its active grants (GET /v1/reporting-grants), or contact Evinor to enable the entitlement. Retrying the same request will not succeed until the entitlement changes.