Toolman

HTTP 403 — Forbidden

4xx Client Error

What it means

The server understood the request and knows who you are, but you are not allowed to do this. Authentication will not help.

What to do about it

Check the account's roles or scopes. On static hosting, a 403 on a directory usually means directory listing is disabled or file permissions are wrong.

Where it sits

403 belongs to the 4xx family: The request contains something the server will not or cannot process. The fix is normally on the client side.

HTTP/1.1 403 Forbidden

Checking it yourself

# see the status code and headers only
curl -sI https://example.com/path

# follow redirects and print each hop
curl -sIL -o /dev/null -w "%{http_code} %{url_effective}\n" https://example.com/path

# JavaScript
const r = await fetch(url);
console.log(r.status, r.statusText);

How this code behaves

Cacheable by defaultNo — caches must not store this response unless explicit cache headers permit it.
Safe to retryNo. Retrying an identical request will produce the same result — the request itself must change.
Effect on search indexingNo direct effect.

Returning 403 correctly

# nginx
return 403;

# Express
res.status(403).json({ error: 'Forbidden' });

# Go
w.WriteHeader(403)

# Python (Flask)
return jsonify(error='Forbidden'), 403;

Frequently asked questions

What does HTTP 403 mean?

The server understood the request and knows who you are, but you are not allowed to do this. Authentication will not help.

How do I fix a 403 error?

Check the account's roles or scopes. On static hosting, a 403 on a directory usually means directory listing is disabled or file permissions are wrong.

Is 403 a client or server problem?

A client problem by definition — the request needs to change. That said, a 4xx can still be the server’s fault if it is misconfigured and rejecting valid requests.

Other 4xx codes

All HTTP status codes