# Forbidden

> The credential is valid but lacks the scope or project access the operation needs.

Source: https://nodus-platform-site.pages.dev/docs/reference/errors/forbidden/
Build revision: 211ad9f836655b1c3a2668c4693e442471f28614

<!-- Code generated by tools/errgen. DO NOT EDIT. -->

**HTTP status:** 403 · **Retryable:** no

The credential is valid but lacks the scope or project access the operation needs.

## Message

```text
{principal} cannot {verb} {resource}{where}: missing scope {scope}
```

## What to do

ask an org admin for the {scope} scope, or use a key that has it (`nodus auth can-i {verb} {resource}`)

## On the wire

The response is a Kubernetes `Status` with `reason: Forbidden` and `code: 403`, plus `fix`, `docs` (this page) and `requestId`. `details.causes` lists the fields involved, when there are any. The CLI prints the fix and the request id; the Python SDK raises `nodus.errors.Forbidden`.

`details` also carries:

* `missingScope`, which the Python SDK exposes as `missing_scope`
