ErrorCode 010 "Not allowed" means your API user is not permitted to process raw card details, not that the credentials are wrong. Handling raw PAN data requires full PCI compliance (SAQ D) and Adyen has to enable the permission on your account, so contact Adyen support and ask for raw card processing permission. If you do not want the PCI burden, switch to the client-side encryption (CSE) flow instead: the card is encrypted in the browser and your server only ever sees the encrypted blob, which needs no special permission.

Context: Stack Overflow #47330297 (top answer, 8 votes): The reporter called the Adyen JSON API for a test payment and got back 403 with errorCode 010, message "Not allowed", errorType security. Their code followed the official PHP sample and the API user existed, so the failure looked like a credentials problem when it was really a permissions one.