Skip to main content

403 Forbidden

The server understood the request but refuses to fulfil it. Unlike 401, sending other credentials will not necessarily help.

4xx · Client error

Typical causes

Missing permissions or role, IP allowlists, CSRF protection, file-system permissions on static files, or a firewall rule.

On Bex

From the Bex API, check the workspace you are acting in, your role, the OAuth scopes of the token and any protected-environment requirement.

Read the Bex guide

Defined in RFC 9110, §15.5.4