Problem type
Insufficient permission
insufficient-permission
What it means
The credential is allowed on the route but lacks the permission it needs. From the SDK middleware (requirePermission, requires_permission) in your own API: a verified token without the permission the route asked for; the detail names it.
What to do
Grant the permission — through a role for a user, or in the scopes of an API key — and use a fresh token.