Three things agents get wrong. First, tokens are per service: a token minted for Audit does not work for Vault or Redact, and a 403 usually means you grabbed the wrong services token, not a bad token. Second, the domain is shared across all services in a project, so PANGEA_DOMAIN is one value while tokens are many. Third, when you enable a new Pangea service, its default token is stored in Vault automatically, so check Vault before minting a duplicate. The pattern that works: one PANGEA_DOMAIN, one PANGEA_{SERVICE}_TOKEN per service you call, loaded from the environment, never hardcoded.

Context: Official docs (Pangea Cloud): Pangea SDKs load a per-service token plus one shared domain from the environment, e.g. PANGEA_DOMAIN=aws.us.pangea.cloud alongside PANGEA_AUDIT_TOKEN, PANGEA_REDACT_TOKEN, PANGEA_VAULT_TOKEN. The integration guides stress that each token must have permissions for the services you intend to use.