# `KEY_SCOPE_DENIED` (HTTP 403): the key lacks the scope this endpoint needs

The secret key was created with a limited set of scopes (email, ip, phone, address, entity, consistency, account), and the endpoint belongs to a family it does not cover.

Scopes let a key for one integration reach only the product it needs: a signup form's key can verify email without being able to spend on IP or phone lookups. A key created without choosing scopes has every scope.

Nothing is billed for a refused request.

**What to do.** Create a key with the scope the integration needs and use that one. Scopes are set at creation; Rotate issues a replacement carrying the same scopes, so a change of scope is a new key rather than a rotation.

```json
{
    "success": false,
    "error": {
        "code": "KEY_SCOPE_DENIED",
        "message": "This API key is not allowed to call ip endpoints. Create a key with the ip scope.",
        "request_id": "req_01m1kgdm4xngzmbmff68g94w0c"
    }
}
```

Reference: https://spaw.co/docs/errors/KEY_SCOPE_DENIED
