DevToolPal
EN
4xx Client errors

403 Forbidden

What it means

The server understood the request but refuses to authorize it. Logging in again will not help unless permissions change.

Common causes

  • The user lacks the required role or scope
  • IP blocking, WAF or bot protection
  • File permissions or a missing index file on the web server

How to fix it

As a client or visitor

Check that your account or token has the right permissions or scopes. On a website, a VPN, blocked IP or bot challenge can cause it.

As the site or API owner

Check file ownership and permissions, directory index settings, and WAF rules. Return 404 instead if you do not want to reveal that the resource exists.

Example response

HTTP/1.1
HTTP/1.1 403 Forbidden
Date: Tue, 07 Oct 2025 09:30:00 GMT
Server: nginx
Content-Type: application/problem+json

{
  "type": "about:blank",
  "title": "Forbidden",
  "status": 403,
  "detail": "You do not have permission to delete this project."
}

Specification

RFC 9110 §15.5.4

FAQ

› Why does nginx return 403 Forbidden?

Commonly: the worker cannot read the files, there is no index file and autoindex is off, or a deny rule matches.

› Should I return 403 or 404 for private resources?

404 hides the resource's existence; 403 is more honest. GitHub, for example, returns 404 for private repositories.