🔍 What This Article Covers
If every call to the Search Atlas External API — including the token/validate endpoint — returns an HTTP 403 error with the message "Invalid scope provided. Check API Key permissions on your Press Releases account!", your API key is missing the press-release scope. This article explains what causes this error and the exact steps to resolve it.
⚠️ Understanding the 403 Error
The 403 error means the API key you are using does not have permission to access the Press Releases (External API) scope. This is not a network issue or a bug in your integration code — it is a permissions configuration issue on your Search Atlas account. Until the correct scope is enabled, every API call, regardless of endpoint, will be rejected with this message.
Common situations where this happens:
- You recently generated a new API key but did not assign all required scopes.
- Your account plan was changed and certain scopes were reset.
- A team member created the API key without enabling the press-release permission.
- You are using an older hardcoded token that no longer has the correct permissions.
🛠️ How to Fix the Scope Error
Follow these steps to check and update your API key permissions inside Search Atlas.
- Log in to your Search Atlas account.
- Click your profile icon or account name in the top-right corner of the platform.
- Navigate to Account Settings and select the API Keys or Integrations section.
- Locate the API key you are using for Signal Genesys or your External API integration.
- Click Edit or Manage Permissions on that key.
- Ensure the press-release scope (also labeled External API in some views) is toggled on.
- Save your changes.
- Re-run your token/validate call to confirm the 403 error is resolved.
Important: If you do not see an option to enable the press-release scope, your current account plan may not include External API access. Contact our team using the chat widget to verify your plan includes this feature.
🔑 Best Practices for API Key Setup
To avoid scope errors in the future, follow these recommendations whenever you create or rotate API keys:
- Always review the full list of scopes before saving a new API key.
- Enable only the scopes your integration actually needs — but do not accidentally leave required scopes unchecked.
- Avoid hardcoding API tokens directly in your application code. Use environment variables or a secrets manager so tokens can be rotated without a code deployment.
- After rotating a key, immediately run a validation call (token/validate) to confirm the new key has the correct permissions before pushing to production.
- Document which scopes each integration requires so your team can replicate the setup consistently.
📋 Signal Genesys Integration Checklist
If you are connecting Signal Genesys to Search Atlas via the External API, confirm all of the following before testing:
- Your API key has the press-release scope enabled.
- You are using the correct base URL and OAuth client credentials flow (not a legacy hardcoded token).
- Environment variables in Signal Genesys are up to date with the current key and endpoint values.
- You have tested the token/validate endpoint independently before making other API calls.
💬 Still Seeing the 403 Error?
If you have followed all the steps above and the error persists, it is possible that the press-release scope needs to be enabled on your account at the platform level by our team. If you need further assistance, open the chat widget in the bottom-right corner of the platform and type human teammate to be connected with a member of our team.