Plain-language meaning
What HTTP code 403 means
RFC 9110 defines 403 Forbidden as a response where the server understood the request but refuses to fulfill it. A reason may appear in the response content, but the status itself does not specify one. RFC 9110 adds that if authentication credentials were provided in the request, the server considers them insufficient to grant access, and that an origin server wishing to hide the existence of a forbidden resource may instead return 404 Not Found.
Keep the code in its namespace
What this code does—and does not—tell you
HTTP 403 is a protocol status. It is not automatically a Roblox client error, an invalid-password message, or proof that an entire site is offline. The server may refuse a request for reasons unrelated to credentials. It also differs from 401 Unauthorized: 401 signals that authentication is required or has failed, whereas 403 means the server refuses the request even when the client is authenticated.
Conservative next step
Where to check next
If you are visiting a site, read any explanation shown with the response and use that site's official support channel if access should be available. If you operate the service, inspect the request and access policy; RFC 9110 says clients should not automatically retry with the same credentials.
Primary source
Read the official reference
This explanation is scoped to the linked IETF / RFC Editor material, checked September 28, 2026. The original source takes priority and may change its instructions.
RFC 9110, Section 15.5.4: 403 ForbiddenSame code system
More HTTP error codes
429 error code: too many requests
HTTP 429 Too Many Requests indicates rate limiting: a user sent too many requests in a given amount of time.
Read this code guide HTTP · 500500 error code: internal server error
HTTP 500 Internal Server Error is a general server response for an unexpected condition; it does not name a specific cause.
Read this code guide HTTP · 503503 error code: service unavailable
HTTP 503 Service Unavailable means a server is temporarily unable to handle a request, such as during overload or scheduled maintenance.
Read this code guide