## TL;DR

The field name in your payload is wrong: a typo, a label instead of the API name, or a field that is read-only on this object. Call describe on the object to list the real API names and their writable flags, fix the mapping, and retry.

## Error

```text
[ {
  "message" : "Unable to create/update fields: AccountNumber__c. Please check the security settings of this field and verify that it is read/write for your profile or permission set.",
  "errorCode" : "INVALID_FIELD_FOR_INSERT_UPDATE",
  "fields" : [ "AccountNumber__c" ]
} ]
```

## Steps

1. Read the fields array; it names the exact offending field. Expected: you know which mapping entry to fix.
2. Call describe on the object (GET /services/data/vXX.X/sobjects/Lead/describe) and search the fields list for the name. Expected: you see whether it exists and its exact API name.
3. Check the updateable and createable flags on that field in the describe output. Expected: false on either explains the rejection.
4. Fix the mapping: use the API name (often with __c for custom fields), not the label. Expected: the payload field names match describe exactly.
5. If the field exists but is not writable for the integration user, grant field-level security or remove it from the payload. Expected: the write succeeds.

## When to use

- Any Salesforce write fails with INVALID_FIELD_FOR_INSERT_UPDATE.
- An agent's field mapping worked on one object and fails on another (different API names).
- After a managed package upgrade renamed or removed a field.

## When not to use

- FIELD_CUSTOM_VALIDATION_EXCEPTION (rule fired on a valid field).
- Required-field-missing errors (the field is right, the value is absent).

## Tool compatibility

- Salesforce REST, SOAP, and Bulk APIs; describe calls on standard and custom objects.
- Any ETL or agent that maps source columns to Salesforce fields.

## Variant phrasings

### Unable to create/update fields

The long form; check the API name and the read/write flags.

### INVALID_FIELD_FOR_INSERT_UPDATE on __c fields

Usually a renamed custom field or a label used instead of the API name.

## Why it happens

Labels and API names differ, custom fields need the __c suffix, and some fields (formulas, rollups, audit fields) are never writable. Payloads built from UI labels or stale schemas hit all three.

## Edge cases

- Field-level security can make a field invisible to the integration user, which surfaces as this error rather than a permissions error.
- Person account fields exist on Account but not on Contact; mapping the wrong object gives this error.
- Describe output is cached by some clients; re-fetch after a schema change.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_cl1VAQkOt97d9pvPcgVhNw
