403 Forbidden

Free

The server understood the request and refuses to authorise it.

What it means

Authenticated but not permitted. Re-authenticating will not help, so do not send the client back to a login page. One deliberate exception: to avoid confirming that a resource exists to someone not allowed to see it, return 404 instead of 403.

Class
4xx Client error
Defined in
RFC 9110 §15.5.4
Cached by default
No

When you receive a 403

  • The server knows who you are, and the answer is no. Signing in again will not change it.
  • Find the role, scope or permission the endpoint needs and check the token carries it - the scopes are in its payload.
  • On a web server, a 403 for a static file often means file permissions, or a directory with no index file and listing turned off.

When you send a 403

  • When the caller is authenticated but not permitted.
  • Name the missing permission, unless naming it would itself reveal something.
  • To hide that a resource exists from someone who may not see it, return 404 instead.

On the wire

HTTP/1.1 403 Forbidden
Content-Type: application/json

{"error": "insufficient_scope", "required": "orders:write"}

Often confused with