When Flink on Confluent Cloud rejects your API key, create a key scoped to the Flink compute pool itself, not the Kafka cluster. Double-check the Table API endpoint properties use a bare hostname with port 443 and that the organization, environment, and pool IDs match the pool youre targeting.

Context: Confluent agent-skills (confluent-cloud-setup): API key permission errors on Flink usually mean the key was created for the Kafka cluster, not the Flink compute pool. Table API connections also fail when the endpoint properties still carry an https:// prefix or the wrong port; the properties expect a bare host on port 443.