Company not granted to this API key

company_not_granted HTTP 403

The X-Yeti-Company header names a company this key is not bound to. Single-company keys ignore the header entirely, so seeing this means the key is multi-company and the value is one it was not granted.

How to react to this in code

Switch on the code member — company_not_granted — which is stable. Do not parse the type URI: it points here, and where "here" is may change.