Scopes
Use the minimum scopes needed by each integration and use separate keys for separate clients or environments.
Authentication failures
401: the credential is missing, invalid, expired, or revoked.403: the credential is valid but lacks the required scope.
Authorization header. OAuth 2.1 is not advertised as available until the complete production authorization profile is configured and verified.