403 Forbidden
The server understood the request but refuses to authorize it.
| Class | Client error (4xx) |
|---|---|
| Defined in | RFC9110, Section 15.5.4 |
| Cacheable by default | No, unless explicit freshness headers allow it |
Common causes
- The user is authenticated but lacks permission for the resource.
- Server rules such as IP blocks, disabled directory listing or WAF rules.
- File system permissions on the server.
What to do
Check the account's permissions and any access rules or firewall in front of the site. Servers sometimes return 404 instead of 403 on purpose to hide that a resource exists.
Related codes
- 401 Unauthorized: The request lacks valid authentication credentials for the target resource.
- 404 Not Found: The server cannot find the requested resource.
- 429 Too Many Requests: The client has sent too many requests in a given amount of time (rate limiting).