Forbidden — this request's workspace is closed to it.
Three cases return this:
- The access token is limited to specific workspaces (see the workspace selection made when
the key was provisioned, or the workspaces approved on the OAuth consent screen) and the
request acts on a workspace outside that set.
- The access token is limited to specific workspaces and the request's workspace could not be
determined at all. The gate is fail-closed, so a workspace-limited token is denied rather
than allowed through when the target workspace is ambiguous.
- The workspace's team has no active ClickFunnels subscription: it was canceled, is paused,
or is locked out after failed payments. Reads and writes are both refused until the
subscription is reactivated, and the body carries "code": "subscription_inactive".
A token with no workspace restriction never receives the first two.