The credential is valid but not permitted to do this. Where a more
specific reason exists you will get insufficient_scope or
company_not_granted instead, so this one means the restriction is
not about scopes or company binding.
Switch on the code member — forbidden — which is
stable. Do not parse the type URI: it points here, and where
"here" is may change.