Possible solution: Check whether the user who retrieved the access token has sufficient rights in Twinfield. We recommend retrieving the token with a user who has all rights in Twinfield, but at the very least full access to the management of master data, purchase invoices, and adding attachments/files. If necessary, retrieve a new access token. The following article explains how to do this from Elari:
this article in the Knowledge base If the rights are sufficient, then check whether the correct administration number is being called. In the menu Application Management / General / Administrations, the field 'Number in financial package' must contain the administration number from Twinfield.