Documentation / API Troubleshooting / 403 Forbidden

403 Forbidden

403 Forbidden troubleshooting for PanelConfig API integrations.

Meaning

A 403 means the token was accepted but the authenticated user is not allowed to access the endpoint. In the deployed build this is usually caused by admin-only endpoint checks.

Checklist

  1. Call /api/v1/me.php with the same token.
  2. Confirm the exact route exists in /api/v1/.
  3. Use the file-based .php path unless your deployment has route rewriting.
  4. Check whether the endpoint requires an admin-capable user.
  5. Check rate-limit behavior and reduce polling if needed.
  6. Review API request records and server/PHP logs.

Example

curl -i https://panel.example.com/api/v1/me.php \
  -H "Authorization: Bearer pc_YOUR_TOKEN" \
  -H "Accept: application/json"

Recovery

  • Do not retry writes blindly in future write endpoints.
  • Rotate tokens if secret exposure is suspected.
  • Use staging to reproduce integration failures.
  • Escalate with timestamp, route, HTTP status, and response message.

Error Handling

flowchart TD
    A[API Request] --> B{Token Valid}
    B -- No --> C[401 Unauthorized]
    B -- Yes --> D{Role Allowed}
    D -- No --> E[403 Forbidden]
    D -- Yes --> F{Rate Window OK}
    F -- No --> G[429 Rate Limit]
    F -- Yes --> H[Return JSON]
← 401 Unauthorized 404 Not Found →