What it means
The server understood the request but refuses to authorize it. Logging in again will not help unless permissions change.
Common causes
- The user lacks the required role or scope
- IP blocking, WAF or bot protection
- File permissions or a missing index file on the web server
How to fix it
As a client or visitor
Check that your account or token has the right permissions or scopes. On a website, a VPN, blocked IP or bot challenge can cause it.
As the site or API owner
Check file ownership and permissions, directory index settings, and WAF rules. Return 404 instead if you do not want to reveal that the resource exists.
Example response
HTTP/1.1 403 Forbidden
Date: Tue, 07 Oct 2025 09:30:00 GMT
Server: nginx
Content-Type: application/problem+json
{
"type": "about:blank",
"title": "Forbidden",
"status": 403,
"detail": "You do not have permission to delete this project."
} Specification
FAQ
› Why does nginx return 403 Forbidden?
Commonly: the worker cannot read the files, there is no index file and autoindex is off, or a deny rule matches.
› Should I return 403 or 404 for private resources?
404 hides the resource's existence; 403 is more honest. GitHub, for example, returns 404 for private repositories.