Independent technical referenceOfficial site
  • Software and systems
  • HTTP service

403

HTTP 403 Forbidden: the server understood the request but refuses it

Verified with sources2 sourcesReviewed Aug 22, 2026
Technician coming? See what they must show you

Risk level

Low

Usually safe to check without specialist tools.

Urgency

Medium

Quick answer

HTTP 403 means the server understood the request but refuses to fulfill it; repeating the same credentials automatically is not recommended.

Safety first

Stop and check this first

  • Do not weaken access controls, make a private resource public or paste an access token to bypass 403. Fix the intended policy or identity assignment.

Safe checks you can perform

  • Read the safe part of the denial response
  • Compare the required permission and active identity
  • Locate the denying layer

Leave these tasks to a qualified professional

  • Do not attempt this professional task: Trace the authorization decision

What a technician must be able to justify

A technician is coming

These are the steps they must carry out and show you. Tick them as they work: if steps are skipped, do not accept a part swap.

These are not instructions for opening or handling the equipment yourself. They are the checks that should support a technical conclusion.

  1. Trace the authorization decision

    What they doCorrelate the request with identity, policy and resource logs and identify the exact deny rule without exposing secrets.

Before accepting a part or repair

Nothing has been shown yet. Do not accept a part swap based on the code alone.

Checks and evidence, step by step

Follow the documented order. An error code identifies the affected system, but it does not prove by itself which part has failed.

  1. 1

    Read the safe part of the denial response

    Tools required

    Procedure

    Record the request ID, policy code and public explanation without copying credentials, cookies or private resource names.

    Do not weaken access controls, make a private resource public or paste an access token to bypass 403. Fix the intended policy or identity assignment.

    Evidence: RFC 9110 section 15.5.4 - 403 Forbidden · IANA Hypertext Transfer Protocol Status Code Registry

  2. 2

    Compare the required permission and active identity

    Tools required

    Procedure

    Verify the documented role or scope and confirm which account, token audience and environment the client actually used.

    Do not weaken access controls, make a private resource public or paste an access token to bypass 403. Fix the intended policy or identity assignment.

    Evidence: RFC 9110 section 15.5.4 - 403 Forbidden · IANA Hypertext Transfer Protocol Status Code Registry

  3. 3

    Locate the denying layer

    No special tools

    Procedure

    Use response identifiers and controlled logs to distinguish an origin authorization decision from an edge or gateway policy.

    Do not weaken access controls, make a private resource public or paste an access token to bypass 403. Fix the intended policy or identity assignment.

    Evidence: RFC 9110 section 15.5.4 - 403 Forbidden · IANA Hypertext Transfer Protocol Status Code Registry

Where this code applies

A code is meaningful only inside the right product and version context.

Primary scope

System
Software and systems
Brand
HTTP
Product type
HTTP service

Known code variants

  • 403 Forbidden
  • 403 Interdit
  • 403 Prohibido
  • 403 Verboten
  • 403 Vietato
  • access to www.roblox.com has been denied
  • código de error 403
  • código HTTP 403
  • error 403 roblox
  • Error Code 403
  • error HTTP 403
  • HTTP 403
  • HTTP error 403
  • HTTP status 403
  • roblox 403
  • se denegó el acceso a www.roblox.com
  • status code 403

What it means

Credentials can be valid yet insufficient, but a 403 can also be unrelated to authentication. An origin may return 404 instead when it wants to hide a forbidden resource.

Warnings and stop conditions

  • Higheditorial warning

    Do not weaken access controls, make a private resource public or paste an access token to bypass 403. Fix the intended policy or identity assignment.

    Evidence: RFC 9110 section 15.5.4 - 403 Forbidden · IANA Hypertext Transfer Protocol Status Code Registry

Symptoms and causes

Probable causes · in order

  • The authenticated identity lacks permissionConfirmed

    The supplied identity can be valid while its role, scope or policy does not allow this resource or action.

    Evidence: RFC 9110 section 15.5.4 - 403 Forbidden · IANA Hypertext Transfer Protocol Status Code Registry

  • A non-credential policy denied the requestPossible

    Origin, edge or security policy can refuse a method, location, network or request characteristic independently of login.

    Evidence: RFC 9110 section 15.5.4 - 403 Forbidden · IANA Hypertext Transfer Protocol Status Code Registry

Virtual technician

Does 403 still appear after these checks?

Answer a few questions to narrow down the likely cause and the safest next action. Guidance only - it never replaces a professional.

Sources and technical references

  1. 1

    RFC 9110 section 15.5.4 - 403 Forbidden

    Internet Engineering Task Force · 2022 · official_doc

  2. 2

    IANA Hypertext Transfer Protocol Status Code Registry

    Internet Assigned Numbers Authority · 2025 · official_doc

Sources: RFC 9110 section 15.5.4 - 403 Forbidden · IANA Hypertext Transfer Protocol Status Code Registryreviewed 2026-08-22 · verified

Was this entry useful?