HTTP 403 – Forbidden
The client does not have access rights to the content, even though it may be authenticated.
Common use case
Returned when a logged-in user tries to access a resource their role or permissions don't allow, e.g. a regular user hitting an admin-only endpoint.
Example
HTTP/1.1 403 Forbidden
{"error":"You do not have permission to view this resource"}History
Part of HTTP/1.0 (RFC 1945, 1996).
Did you know?
Unlike 401, re-authenticating won't fix a 403 - the server already knows who you are and has decided you're not allowed in.