What it means
Authenticated but not permitted. Re-authenticating will not help, so do not send the client back to a login page. One deliberate exception: to avoid confirming that a resource exists to someone not allowed to see it, return 404 instead of 403.
- Class
- 4xx Client error
- Defined in
- RFC 9110 §15.5.4
- Cached by default
- No
When you receive a 403
- The server knows who you are, and the answer is no. Signing in again will not change it.
- Find the role, scope or permission the endpoint needs and check the token carries it - the scopes are in its payload.
- On a web server, a 403 for a static file often means file permissions, or a directory with no index file and listing turned off.
When you send a 403
- When the caller is authenticated but not permitted.
- Name the missing permission, unless naming it would itself reveal something.
- To hide that a resource exists from someone who may not see it, return
404instead.
On the wire
HTTP/1.1 403 Forbidden
Content-Type: application/json
{"error": "insufficient_scope", "required": "orders:write"}