forbidden
type: https://docs.d2b.dev/errors/forbidden — Not allowed. Typical status: 403, or 402 when the cause is a paused workbook.
A missing scope (a workbooks:write operation called with a workbooks:read key; deleting a workbook, dropping a table, restoring a snapshot or reverting a version needs workbooks:delete), a governance policy refusal (reading a denied column, raw-byte preview / revise on a governed workbook), or a PAT reaching outside its pin — the workbook or workspace it is scoped to, or the account it is bound to, including an explicit workspace_id the credential cannot address.
Paused workbooks (402)
Section titled “Paused workbooks (402)”A 402 with this type means the owner’s free trial has ended and their workbooks are paused: reads and writes are refused, but nothing was deleted and the data is untouched. Every surface answers the same way — REST, MCP, the SDKs and the agent tools — because the check sits at the single point where a workbook is opened.
Taking up any plan (pay-as-you-go with a card on file is $0/month) resumes every paused workbook immediately. There is no restore step and no waiting: the objects were never moved.
What to do
Section titled “What to do”detailsays which scope or policy is the cause. Mint a PAT with the required scope; for ad2b logincredential,suggested_fix_clinames the login command to re-run (a login holds the whole workbooks family unless--scopesnarrowed it)- For policy causes,
GET .../tables/{name}/accessdry-runs what would be masked / denied - A pinned PAT not reaching another workbook or workspace is the intended least privilege;
GET /api/v1/me/workspaceslists what a credential reaches - On a 402, do not retry and do not re-mint the PAT — neither is the cause. Take up a plan, then replay the request unchanged
All error types: Reading errors.