Problem type
Insufficient scope
insufficient-scope
What it means
On the management API, a credential whose kind cannot hold the route's scope level, or is outside the kinds the route allows. On the account API, a token without the self_service scope.
What to do
Use a kind of credential the route accepts. For the account API, add self_service to the client's allowed_scopes and request it at sign-in.