403 Forbidden

The server understood the request but refuses it.

Code
403
Reason phrase
Forbidden
Class
4xx Client error
Defined in
RFC 9110 section 15.5.4
Cacheable by default
No

What it means

Client error: the problem lies with the request. Repeating it unchanged will normally fail again.

When a server should send it. When the server understood the request and refuses it whatever credentials are offered: no permission for this user, a blocked address, a directory without an index. A server that does not want to reveal the resource exists may send 404 instead.

Common causes. Missing permissions, a firewall or bot rule blocking you, a folder without an index page, or file permissions the web server cannot read.

What to do. If it is your site, check file permissions (644 for files, 755 for folders), .htaccess rules and the firewall. As a visitor, try without a VPN, since some sites block their addresses.

How clients and crawlers treat it

Browsers and HTTP clients. Browsers show the body. Signing in again does not help, unlike 401, so clients should not loop on retries.

Google Search. Like every 4xx except 429, it tells Google the content does not exist: an indexed URL is removed from the index, and a new one is not processed. Crawl frequency for the URL gradually drops. Google advises against using 401 or 403 to slow Googlebot down; use 429 or 503 for that. Source: Google Search Central, How HTTP status codes, and network and DNS errors affect Google Search.

Caching. Not cacheable by default (RFC 9110 section 15.1 does not list it). A cache stores it only when the response says so with Cache-Control or Expires.

Example response

HTTP/1.1 403 Forbidden
Content-Type: text/html; charset=utf-8

Forbidden

How to send 403

nginx
location /example {
    return 403;
}
Apache (.htaccess)
RewriteEngine On
RewriteRule ^example$ - [R=403,L]
PHP
http_response_code(403);
echo 'Forbidden';
exit;
Node.js
res.writeHead(403, { 'Content-Type': 'text/plain' });
res.end('Forbidden');
Python (Flask)
# in a view function
return 'Forbidden', 403

Change the paths to suit. In nginx, add_header needs always to apply to error responses.

Related codes

All status codes · All 4xx codes

Names and numbers from the IANA HTTP Status Code Registry. Google Search behaviour as documented by Google Search Central.