## **🔎 What the 403 error means**

A **403 Invalid scope provided** response means the access token does not include the scope required by the endpoint. The request may be correctly formatted, but the token was issued without the permission the API checks.

This is different from an expired or invalid token. Repeating the request with the same token will continue to return 403 until the token is issued with the correct scope.

## **⚙️ How Signal Genesys authentication works**

Each Signal Genesys endpoint defines one or more required scopes. Your authentication setup must request those scopes, and the Signal Genesys authorization service must approve them for the client or application.

Scopes are controlled by Signal Genesys and the client configuration used for your integration. Search Atlas cannot add, approve, or enable a Signal Genesys scope from the Search Atlas interface.

## **✅ Verify your configuration**

1. Confirm that you are using the current Signal Genesys API base URL and endpoint documentation.
2. Check the endpoint’s required scope and copy it exactly, including capitalization, punctuation, and separators.
3. Review the token response and confirm that the returned **scope** value contains the required permission.
4. Request a new token after changing scopes. Existing tokens do not gain newly approved permissions.
5. Send the token as an authorization header using the format **Authorization: Bearer YOUR\_ACCESS\_TOKEN**.
6. Make sure the token was issued for the same environment, client, and API host as the request.

## **🚫 Common causes of invalid scopes**

- The scope was omitted from the token request.
- The scope name was typed incorrectly or uses an unsupported alias.
- The client is not approved for that scope.
- A token from another environment or application is being reused.
- The integration is using an authentication flow that does not support the required scope.
- The API documentation and deployed endpoint require different scope names.

## **👤 Is a Search Atlas account required?**

A Search Atlas account is required when you use a Search Atlas feature or workflow that connects to Signal Genesys. However, having a Search Atlas account does not automatically grant Signal Genesys API access or the scopes required by external endpoints.

For a direct Signal Genesys API integration, access depends on Signal Genesys client registration, authorization, and scope approval. Confirm the required account and client setup with the Signal Genesys API owner or administrator.

## **🛠️ When to request configuration help**

If every endpoint returns the same invalid-scope response, provide your integration owner with the endpoint, HTTP method, requested scope, token response scope, client environment, and request timestamp. Do not share client secrets or full access tokens.

Ask the API owner to confirm that the client is approved for the exact scope and that the selected authentication flow can issue it. Search Atlas support can help review how the Search Atlas workflow is configured, but cannot grant Signal Genesys permissions.

If you need further assistance, open the chat widget in the bottom-right corner of the platform and type **human teammate** to be connected with a member of our team.