403 Forbidden

Every error of the Spillard Connect API is an RFC 9457 application/problem+json body whose type points here. Branch on errorCode, never on title or detail.

Not retryable as is: change the request, the token or the target before sending it again.

errorCodeMeaning
auth.fleet_restrictedYour client reads this organization for some of its fleets only, and the operation needs all of them (creating a fleet or an API client, managing webhooks). Use an organization your client reads in full.
auth.scope_missingThe token lacks the scope the operation requires, or the request names a scope your client does not hold. Grant the scope to the API client and get a new token.
auth.tenant_forbiddenThe organization is outside your client's access, the request needs sub-organization access your client lacks, or the token's access list is damaged. Check `access` in `GET /v1/context`, or ask your Spillard account manager to change your client's access.
data.retention_restrictedThe data is older than the organization's data access allows (see `dataAccessDays` in `GET /v1/context`). Ask for newer data.
event.share_restrictedThe event cannot be shared by link: its page would show data outside what your client may read. Do not share this event, or ask your Spillard account manager for wider access for your client.

The full registry is the top-level x-error-codes list (and the ErrorCode schema) of /openapi/v1.json; the API reference is at /scalar.