not-entitled
HTTP status: 403 Forbidden
Type URI: https://docs.evinor.ai/problems/not-entitled
The API key carries the scope the endpoint requires, but the account that owns the key is not entitled to the operation. Evinor re-checks the owner's entitlement on every call, so a key keeps working only while its owner keeps the entitlement.
This is different from missing-scope: that one is
fixed by minting a key with the right scope, this one is fixed on the account.
The body carries a code member naming the check that failed: FORBIDDEN
(filing as yourself), GRANT_FORBIDDEN (filing under any grant), or
GRANT_NOT_USABLE (this particular grant_id). See
Reporting events.
Common causes
- Submitting a report (
POST /v1/reports) from an account that does not have structured reporting enabled, or no longer has it. - Submitting under a
grant_idthe account cannot use — a grant that does not exist, was issued to someone else, was revoked, has expired, or is for a different event type. The response deliberately does not say which. - Submitting under a
grant_idfrom an account without the reporting-grant entitlement.
How to resolve
Check the account's plan and its active grants (GET /v1/reporting-grants), or
contact Evinor to enable the entitlement. Retrying the same request will not
succeed until the entitlement changes.