administrator/write scope, which is reserved for Kobble-internal credentials and is not granted to client API credentials — requesting it at the token endpoint will be rejected. Card programs are provisioned for you by Kobble: contact your Kobble representative to have one created for your account, then use the returned program id as program_id when issuing cards. A program must exist before any card can be created.