← All status codes4xx – Client Error

HTTP 403 – Forbidden

The client does not have access rights to the content, even though it may be authenticated.

Common use case

Returned when a logged-in user tries to access a resource their role or permissions don't allow, e.g. a regular user hitting an admin-only endpoint.

Example

HTTP/1.1 403 Forbidden

{"error":"You do not have permission to view this resource"}

History

Part of HTTP/1.0 (RFC 1945, 1996).

Did you know?

Unlike 401, re-authenticating won't fix a 403 - the server already knows who you are and has decided you're not allowed in.