403 Forbidden
The server understood the request but refuses to fulfil it. Unlike 401, sending other credentials will not necessarily help.
4xx · Client error
Typical causes
Missing permissions or role, IP allowlists, CSRF protection, file-system permissions on static files, or a firewall rule.
On Bex
From the Bex API, check the workspace you are acting in, your role, the OAuth scopes of the token and any protected-environment requirement.
Read the Bex guideDefined in RFC 9110, §15.5.4