Per Endor Labs docs: 401 is expiry, 403 is tenant or scope, and SSO refresh needs the root tenant segment.

Context: Problem: The Endor Labs auth check fails. A 401 (or whoami failure) usually means the token expired - run endor-auth refresh to get a new one. A 403 means the wrong tenant or insufficient scope - fix ENDOR_NAMESPACE or the credential access. SSO quirk: endor-auth refresh with -n uses only the root segment of the tenant for the IdP login; after refreshing, set ENDOR_NAMESPACE or pass -n on the workflow CLI for the full child path.