HTTP

403 Forbidden

The server knows who you are but won't let you do this.

What it looks like

Forbidden
You don't have permission to access this resource.

What does "403 Forbidden" mean?

Returned when the server knows (or does not care) who you are and refuses anyway. On shared hosting it usually comes from file permissions or .htaccess rules; on apps and APIs it usually means the account lacks a role or scope.

What causes "403 Forbidden"?

  • You lack permission/role for the resource.
  • File or directory permissions on the server.
  • WAF / hotlink / IP rules.

How do I confirm the cause?

  1. Check whether the 403 page is your app’s or the web server’s (Apache or nginx wording), a CDN’s or a firewall’s — that tells you which layer refused.
  2. For static files, check ownership and permissions (644 for files, 755 for folders) and any deny rules in .htaccess.
  3. For an API, compare the token’s scopes or the user’s role with what the endpoint requires.

How do I fix "403 Forbidden"?

  • Check the user's role/permissions for that action.
  • Check file ownership and permissions (e.g. 644/755).
  • Review any WAF or .htaccess deny rules.

How do I stop it happening again?

  • Set file permissions correctly in your deploy script rather than fixing them by hand.
  • When you add a new permission check, give it a clear error message saying which permission is missing.
Got a different error? Paste it into the Explain This Error tool → Identifies the family and the fix — runs locally, nothing uploaded.

Related errors