administrator/write scope, which is reserved for Kobble-internal credentials and is not granted to client API credentials — requesting it at the token endpoint will be rejected.fees_paid_by: CLIENT requires client_wallet_id referencing an ACTIVE KOBBLE_AUD_1 wallet; violations fail with 400.