401 with cause: "Forbidden" and the message
Forbidden seller resource - permissions <Code>. Only the permissions that SaaS API methods actually
check are listed below. The other checkboxes on the key’s page do not affect the API.
Where to enable permissions
1
Open the API keys page
Manage → School → For developers → API keys (
/manage/school/api-keys).2
Open the key settings
In the row of the key you need, select “Edit”.
3
Select checkboxes and save
The checkboxes are grouped into sections: “School Management”, “Course Management” and so on. Click
“Save”.
If a method lists several permissions, any one of them is enough.
Permissions by task
Choose what your integration should do and enable the corresponding checkboxes.Permission reference
In the error text, the API refers to a permission by its technical code, for exampleForbidden seller resource - permissions FormManage. Use the code in the right column to find which checkbox to enable.
School Management
Course Management
Forms management
Organization Management
Staff Management
This section exists only in corporate schools.Default permissions
A new key immediately receives all the permissions that SaaS API methods need for its school type:- in any school — “School User Management”, “Forms management”, “Course Curator”, “Course Student Management”, “Course Management” and the other permissions in the “School Management” and “Course Management” sections;
- in a commercial school — additionally “School Sales” and “School Refunds”;
- in a corporate school — additionally “Staff Management” and “Staff browsing”.
401 Forbidden seller resource - permissions <Code>, find the checkbox it needs in the tables above.
Differences in corporate schools
In corporate schools, some checkboxes are labeled differently: “Company User Management” instead of “School User Management”. The permission code stays the same. The “School Sales” and “School Refunds” checkboxes are not shown in corporate schools.System permissions
The key’s service user automatically receives the system API client flag (UserIsApiClient) — without
it, SaaS methods do not work. It is not shown in the account, and you do not need to configure it. If a request with
a valid token returns an access error even though all the required checkboxes are enabled, contact
support.
Updated: 2026-09-28 05:04 UTC