HTTP 403 — Forbidden
4xx Client Error
What it means
The server understood the request and knows who you are, but you are not allowed to do this. Authentication will not help.
What to do about it
Check the account's roles or scopes. On static hosting, a 403 on a directory usually means directory listing is disabled or file permissions are wrong.
Where it sits
403 belongs to the 4xx family: The request contains something the server will not or cannot process. The fix is normally on the client side.
HTTP/1.1 403 Forbidden
Checking it yourself
# see the status code and headers only
curl -sI https://example.com/path
# follow redirects and print each hop
curl -sIL -o /dev/null -w "%{http_code} %{url_effective}\n" https://example.com/path
# JavaScript
const r = await fetch(url);
console.log(r.status, r.statusText);
How this code behaves
| Cacheable by default | No — caches must not store this response unless explicit cache headers permit it. |
| Safe to retry | No. Retrying an identical request will produce the same result — the request itself must change. |
| Effect on search indexing | No direct effect. |
Returning 403 correctly
# nginx
return 403;
# Express
res.status(403).json({ error: 'Forbidden' });
# Go
w.WriteHeader(403)
# Python (Flask)
return jsonify(error='Forbidden'), 403;
Frequently asked questions
What does HTTP 403 mean?
The server understood the request and knows who you are, but you are not allowed to do this. Authentication will not help.
How do I fix a 403 error?
Check the account's roles or scopes. On static hosting, a 403 on a directory usually means directory listing is disabled or file permissions are wrong.
Is 403 a client or server problem?
A client problem by definition — the request needs to change. That said, a 4xx can still be the server’s fault if it is misconfigured and rejecting valid requests.