## **🔍 Overview**

If every External API call — including the **token/validate** endpoint — returns an **HTTP 403** error with the message *"Invalid scope provided. Check API Key permissions on your Press Releases account!"*, your API key is missing the **press-release** scope required by the Search Atlas External API (used by Signal Genesys). This article explains what causes the error and walks you through the steps to fix it.

## **⚠️ Understanding the Error**

The 403 response is a permissions error, not an authentication failure. Your API key is recognized, but it has not been granted the scopes needed to access press release endpoints. Common reasons this happens include:

- The API key was created before the **press-release** scope was added to your plan.
- The key was generated with default or limited permissions.
- Your account plan does not currently include External API / press-release access.

## **🛠️ Step-by-Step: Check and Update Your API Key Permissions**

1. **Log in** to your Search Atlas account and navigate to your **Account Settings** (click your profile icon in the top-right corner).
2. Go to the **API Keys** or **Integrations** section within Account Settings.
3. Locate the API key you are using for your External API or Signal Genesys integration.
4. Click **Edit** or **Manage Permissions** on that key.
5. Look for the **press-release** scope (sometimes listed as **External API** or **Press Releases**) and ensure it is **enabled**.
6. Save your changes.
7. Re-run your API call to confirm the 403 error is resolved.

If you do not see a press-release or External API scope option on the key, proceed to the next section.

## **📋 If the Scope Option Is Not Available**

The **press-release** scope may not be visible if it is not included in your current subscription plan. In that case, the scope cannot be enabled from within the API key settings alone — it must be unlocked at the account or plan level first. Here is what to check:

- **Plan eligibility:** Confirm that your Search Atlas plan includes External API and Press Release access. Refer to your plan details in Account Settings under **Billing** or **Subscription**.
- **Regenerate the key:** If the plan is correct but the scope is still missing, try deleting the existing API key and generating a new one. Newly created keys inherit the latest permissions tied to your account.
- **Existing keys:** Keys created before a plan upgrade may not automatically receive new scopes. A fresh key should resolve this.

## **🔗 Reconnecting Signal Genesys After Fixing Permissions**

Once the correct scopes are in place, update the API key in your Signal Genesys configuration so the integration uses the updated credentials:

1. Copy your updated or newly generated API key from Search Atlas Account Settings.
2. Open your Signal Genesys settings and navigate to the **Search Atlas API** or **External API** connection section.
3. Replace the old API key with the new one.
4. Save and test the connection using the **token/validate** endpoint to confirm a successful **200 OK** response.

## **✅ Verifying the Fix**

After updating your key and permissions, verify that the integration is working correctly:

- The **token/validate** endpoint should return **HTTP 200** instead of 403.
- Press release submissions and other External API actions should complete without scope-related errors.
- If you still receive a 403 after following all steps, the issue may require a backend scope assignment on your account that cannot be self-served.

## **💬 Still Seeing the 403 Error?**

If you have completed all the steps above and the error persists, the press-release scope may need to be manually enabled on your account by our team. If you need further assistance, open the chat widget in the bottom-right corner of the platform and type **human teammate** to be connected with a member of our team.