More
More
403 Forbidden
The server understood the request but refuses it.
- Code
403- Reason phrase
- Forbidden
- Class
- 4xx Client error
- Defined in
- RFC 9110 section 15.5.4
- Cacheable by default
- No
What it means
Client error: the problem lies with the request. Repeating it unchanged will normally fail again.
When a server should send it. When the server understood the request and refuses it whatever credentials are offered: no permission for this user, a blocked address, a directory without an index. A server that does not want to reveal the resource exists may send 404 instead.
Common causes. Missing permissions, a firewall or bot rule blocking you, a folder without an index page, or file permissions the web server cannot read.
What to do. If it is your site, check file permissions (644 for files, 755 for folders), .htaccess rules and the firewall. As a visitor, try without a VPN, since some sites block their addresses.
How clients and crawlers treat it
Browsers and HTTP clients. Browsers show the body. Signing in again does not help, unlike 401, so clients should not loop on retries.
Google Search. Like every 4xx except 429, it tells Google the content does not exist: an indexed URL is removed from the index, and a new one is not processed. Crawl frequency for the URL gradually drops. Google advises against using 401 or 403 to slow Googlebot down; use 429 or 503 for that. Source: Google Search Central, How HTTP status codes, and network and DNS errors affect Google Search.
Caching. Not cacheable by default (RFC 9110 section 15.1 does not list it). A cache stores it only when the response says so with Cache-Control or Expires.
Example response
HTTP/1.1 403 Forbidden Content-Type: text/html; charset=utf-8 Forbidden
How to send 403
location /example {
return 403;
}
RewriteEngine On RewriteRule ^example$ - [R=403,L]
http_response_code(403); echo 'Forbidden'; exit;
res.writeHead(403, { 'Content-Type': 'text/plain' });
res.end('Forbidden');
# in a view function return 'Forbidden', 403
Change the paths to suit. In nginx, add_header needs always to apply to error responses.
Related codes
- 401UnauthorizedAuthentication is needed and was missing or wrong.
- 404Not FoundNothing exists at this address, or the server will not say that it does.
- 451Unavailable For Legal ReasonsThe resource is blocked for legal reasons, such as a court order or sanctions.
- 429Too Many RequestsThe client sent too many requests in a given time and is being rate limited.
All status codes · All 4xx codes
Names and numbers from the IANA HTTP Status Code Registry. Google Search behaviour as documented by Google Search Central.