4xx
403 Forbidden
The server understood the request but refuses to authorize it.
What is HTTP 403?
This status code means the server understood the request and the client's identity, but the client does not have permission to access the requested resource. Unlike 401, re-authenticating will not help because the issue is authorization, not authentication. The server knows who you are but you are not allowed to perform this action. The server may or may not explain why access was denied in the response body.
Defined in RFC 9110
Common Causes
- The authenticated user lacks the required role or permission for this resource
- IP-based access restrictions blocking requests from certain addresses or regions
- File system permissions preventing the web server from reading the requested file
- Directory listing is disabled and no index file exists at the requested path
How to Fix
- Verify your account has the required permissions or role to access this resource
- Contact the administrator to request access if you believe you should have permission
- Check server file permissions and ensure the web server process can read the requested files
- If IP-restricted, ensure your request originates from an allowed address