client_token_not_allowed (403)

The credential is valid, but not for this endpoint.

Cause

One of two things:

The message

The wording depends on which of the cases above it was.

A client token can only call POST /v1/scans.
Client tokens are issued with an API key.

The fix

Make every call other than the scan itself from your server, with the API key. Send only POST /v1/scans from the app with the token.

event_id

event_id is always null on this code. It is a refusal the caller is meant to handle, so nothing is recorded as a failure to look at. The service answers and writes one log line.

The whole catalogue, grouped by what a caller does with it, is on errors.

The response

{
  "error": {
    "code": "client_token_not_allowed",
    "message": "A client token can only call POST /v1/scans.",
    "docs_url": "https://doc.cheap/docs/errors/client_token_not_allowed",
    "request_id": "req_9e6b1f7c-2d4a-4b83-9c51-7f0ad3e8b642",
    "event_id": null
  }
}