403 Forbidden on /contacts endpoint during batch updates

Another day of chasing ghosts. The API is throwing a 403 Forbidden on a PATCH request to the /contacts endpoint, but the API_KEY has full permissions for the tenant. This broke our sync for three hours this morning.

Tried rotating the credentials and checking the SCOPE settings. Still nothing.

{
 "error": "Forbidden",
 "message": "The requested action is not allowed for the current user."
}

The calls work fine for single records but fail the second a batch list is passed.

are you sending the batch as a single array or separate requests? we had a similar 403 mess on zoom contact center - inc-4471 was the ticket. usually it’s a payload nesting issue. try checking if the structure matches this:

{
 "contacts": [
 {
 "id": "123-abc",
 "fields": { "status": "updated" }
 }
 ]
}