SIP Trunk 403: Zendesk Voice Integration to Genesys Cloud SIP Trunk Mapping

I’m completely stumped as to why the GET /api/v2/telephony/providers/edges/trunks endpoint fails with a 403 Forbidden error when attempting to retrieve the list of available trunks for mapping Zendesk Voice provider credentials to Genesys Cloud SIP trunk configurations. The migration script is failing specifically during the authentication handshake phase.

We are currently migrating our support operations from Zendesk Sunshine Conversations to Genesys Cloud. The goal is to replicate the existing voice routing logic. In Zendesk, voice interactions were handled via a third-party provider with simple API keys. In Genesys Cloud, we need to set up a dedicated SIP trunk for inbound and outbound calls to maintain continuity.

The request parameters look correct based on the documentation, but the server rejects the request immediately. Here is the error response we are receiving:

{
 "errors": [
 {
 "code": "forbidden",
 "message": "User does not have permission to view SIP trunks. Required capability: telephony:trunk:read"
 }
 ]
}

The user account used for the migration has the admin:telephony:write capability, which I assumed would cover SIP trunk access. However, it seems that specific capability is missing. Is there a separate role or capability required for SIP trunk configuration in Genesys Cloud?

In Zendesk, voice settings were part of the general admin panel. In Genesys Cloud, the permissions seem much more granular. We need to understand the exact capability mapping to proceed. Any practical migration advice on how to structure the admin roles for voice configurations would be greatly appreciated. We are trying to avoid manual intervention for each trunk setup.