Just answered my own question. I baked a new macaroon with invoices:create, invoices:read and payments:read and lo, inbound zaps work! The macaroon might be a tad permissive but I’m not too worried about extra read permissions for those things.
Mind zapping this note a small amount to confirm?