API Error 403 (permission_error)
The credential is valid but not allowed to use this model, org, or endpoint.
235 issues · 42 open · 193 resolved (82%) · first seen Feb 25, 2025
First response · account
What to do now
Most likely: The credential is valid but lacks access to the requested model, organization or policy scope.
- Confirm model availability and organization membership for the active account.
- Check enterprise policy or gateway allow-lists before rotating credentials.
- Capture the permission error body when asking an administrator for access.
These are conservative triage steps, not an official Anthropic fix. Use the issue and workaround evidence below before making a destructive configuration change.
Is this getting better or worse?
This class of problem is holding steady. 65 new reports in the last 90 days vs 75 in the 90 before — -13%. The open backlog peaked at 48 in 2026-07 and sits at 42 today.
Derived by counting each matching issue from its creation date until it closed. First-party
computation over the anthropics/claude-code tracker — the trend is not published
anywhere upstream.
Which builds report this
104 of these reports name the Claude Code build they were running, spanning 61 releases. Heaviest reporters:
- Claude Code v2.1.114
- Claude Code v2.1.220
- Claude Code v2.1.81
- Claude Code v2.1.211
- Claude Code v2.1.92
- Claude Code v2.1.195
- Claude Code v2.1.161
- Claude Code v2.1.12
Report volume, not a defect count: an issue can mention a build without that build having caused the failure. Versions come from the version string in the bug-report template, matched against real published tags.
Do these get fixed?
Median time to close is 14 days across 193 closures. Of the 193 closures with a recorded reason, 31% were closed as completed and 134 as not-planned or duplicate. The most recent completed fix landed in 2026-08.
Workarounds reported by the community
47 of these issues post a workaround someone says worked. The highest-engagement ones:
- [BUG]Cowork network egress allowlist not working - custom domains blocked with 403 blocked-by-allowlist
- …3. Proxy scope - Cowork might use a separate proxy instance Workaround: Run a local proxy bypass: export HTTP PROXY= Similar issues in OpenClaw's sandbox - config and enforcement must be synchronized.
Found in the thread of #30112 · still open - [Bug] Anthropic API Error: Usage credits required for 1M context window with opus-plan model
- …sn't work, and just stops working at 1M Context. A feasible workaround would be to periodically use the /compact command manually.
Found in the thread of #61869 · resolved - [BUG] Claude Code on the Web .NET SDK binary downloads blocked by proxy even with "All domains" network access enabled
- …SL -o /tmp/install.sh Returns: valid 1888-line shell script Workaround None currently. Users must: Have Claude write code Pull and compile locally Report errors back to Claude Repeat until code compiles This significantl…
Found in the description of #11897 · still open - [BUG] Bedrock: Claude Opus 4.7 returns permission_error despite AUTHORIZED entitlement status
- …resolution. I'd appreciate it if anyone could do the same. In the meantime, this doesn't seem to be a technical or configuration issue.
Found in the thread of #51183 · still open - [Bug] Anthropic API Error: OAuth token missing user:profile scope
- …completed successfully but error persists - Still getting: Workaround to try: Based on @gerrywastaken's comment, will try and logging back in instead of . Note: appears insufficient to fix this - requires full logout/lo…
Found in the thread of #11985 · still open
Excerpts are quoted from the linked issue so you can judge relevance before opening it. Threads that only ask for a workaround, or report that there is none, are excluded. These are community suggestions, not official guidance from Anthropic — read the full thread before applying one.
Matching issues 1–100
Ranked by community engagement (reactions weighted over comments).
- [BUG]Cowork network egress allowlist not working - custom domains blocked with 403 blocked-by-allowlist
- [Bug] Anthropic API Error: Usage credits required for 1M context window with opus-plan model
- [Bug] Anthropic API Error: OAuth token missing user:profile scope for usage data
- [BUG] Claude Code on the Web .NET SDK binary downloads blocked by proxy even with "All domains" network access enabled
- [BUG] `AWS_BEARER_TOKEN_BEDROCK` auth broken in 2.1.92+ (regression from 2.1.91)
- [BUG] Bedrock: Claude Opus 4.7 returns permission_error despite AUTHORIZED entitlement status
- [Bug] Anthropic API Error: OAuth token missing user:profile scope
- [BUG] [Cowork] sandbox.network.allowedDomains ignored — external APIs blocked (api.zotero.org, crossref.org, etc.)
- [BUG] Allow network egress - All domains' setting not reflected in session proxy JWT
- Cowork sessions fail with 'Connection error' - internal MITM proxy blocking api.anthropic.com
- Agent Teams: Spawned teammates don't inherit model configuration from team lead
- Claude Code blocked from accessing shared claude.ai conversations
- [BUG] "Claude will return soon" Claude-code down?
- [BUG] Cowork 403 "Request not allowed" on Pro plan - Chat works fine
- [BUG] Sandbox git proxy rejects git push updates to existing main with HTTP 403
- [BUG] Claude Code Web: crates.io blocked by proxy in cloud environment despite being trusted by default
- OAuth login fails due to Cloudflare challenge race condition — auth login / setup-token broken during elevated CF protection
- [BUG] Desktop app SSH remote session fails with 403 Request not allowed while Local session and CLI-over-SSH work fine (same account)
- [BUG] MCP OAuth 403 insufficient_scope step-up authorization does not trigger re-authorization flow
- [Bug] Egress proxy blocks GitHub subdomains, breaking git operations in web bash environment
- [BUG] Claude Code does not handle expiry of short term IAM credentials (security tokens)
- [BUG] Bedrock, 3.7
- [BUG] Claude Pro subscription purchased via iOS App Store not recognized by Claude Code (subscriptionType: null)
- [BUG] Claude Desktop Code/Cowork mode returns 403 "Request not allowed" while CLI and Chat work fine
- OAuth token revoked · Please run /login
- Claude Code does not handle new OAuth after archiving workspace
- [BUG] WebFetch tool always fails — Cloudflare bot protection on claude.ai blocks headless domain verification requests
- [BUG] API Error 403 Please run /login
- [BUG] Claude Code no longer respecting ANTHROPIC_MODEL variables
- [BUG] Claude Desktop stuck on infinite loading spinner at startup due to unhandled OAuth 403 error (Claude Code subscription check)
- [BUG] Claude Code Web default environment prevents fetching of github release artifacts
- [BUG] WebFetch fails with 403 on npmjs.com URLs
- [BUG] Claude will return soon
- [BUG] Claude Code doesn't use scope from WWW-Authenticate during step-up authorization
- [BUG] claude -p not work in 1.0.111
- Feature request: read-only usage scope on `claude setup-token` (or a usage:read grant) for subscription accounts
- [BUG] GitHub repo-scoping gateway returns 403 on github.com even with "All domains" egress, breaking Bazel dependency resolution
- [BUG] Trusted egress allowlist has wrong Docker CDN host — production.cloudflare.docker.com instead of production.cloudfront.docker.com
- Bug Report: API Error: 403 {"error":{"type":"forbidden","message":"Reque...
- [BUG] Dispatch 403 "Request not allowed" and Remote Control not enabled on Pro plan
- [BUG] Voice mode: 'No speech detected' — WebSocket blocked by Cloudflare challenge (403)
- [FEATURE] Add hex.pm to allowed network domains for Elixir/Phoenix development
- [BUG] GitHub proxy 403s release-asset downloads in cloud sessions, breaking builds
- Your organization has disabled Claude subscription access for Claude Code · Use an Anthropic API key instead, or ask your admin to enable access
- [Bug] Anthropic API Error: Permission Denied (403) on Login
- MCP OAuth SDK sends empty User-Agent, causing 403 from WAF/Cloudflare-protected servers
- [Bug] sdk@0.2.96 Bedrock SigV4 regression: 403 auth failure with standard AWS instance profile credentials
- [Feature Request] Allow Google Gemini API (generativelanguage.googleapis.com) in Claude Code Mobile
- [BUG] Task tool subagents don't inherit EU cross-region inference model configuration for AWS Bedrock
- [BUG] Bedrock integration is not working
- [BUG] API Error: 403 {"error":{"type":"forbidden","message":"Request not allowed"}} · Please run /login
- [BUG] Claude Code v1.0.27 with AWS Bedrock gives "API Error: 403 The security token included in the request is invalid."
- Bug Report: I can't use `bedrock`. it requires access to us-east-2 but I...
- Your organization has disabled Claude subscription access for Claude Code · Use an Anthropic API key instead, or ask your admin to enable access
- [BUG] Notion MCP blocked by proxy in Cowork sessions - mcp.notion.com not on allowlist
- Remote triggers: MCP tools fail to load and network proxy blocks outbound HTTP after initial run
- [BUG] Cowork returns 403 on macOS 26.3.1 but works on macOS 26.3
- [FEATURE] WebFetch: Allow access to public claude.ai/share conversation links (Consolidates 4 prior reports)
- If I reach the limit can't send bugreport
- [Bug] Anthropic API Error: Internal Server Error (500)
- [BUG] AWS Bedrock, Calling us-east-2 region instead of the specified region
- Permission denied with aws bedrock but working with aws cli
- [DOCS] Login troubleshooting page missing "OAuth not allowed for organization" guidance
- [BUG] Session is not remembered when login in Windows
- [BUG] Additional allowed domains setting not applied to Claude Code container network egress
- [BUG] Webfetch not working in cloud version
- Bug: single streaming HTTP request outlasting bearer TTL is killed mid-stream; no in-stream renewal path
- [BUG] Claude code --resume is not properly resolving custom model IDs from settings.json
- [BUG] Git proxy returns 403 Forbidden on git-receive-pack
- [FEATURE] Multi-Account Usage Monitoring API for Claude Code
- [BUG] - Incorrectly calling out an issue with API key authentication.
- [BUG] /usage fails with OAuth scope error: "user:profile" scope missing
- [Bug] Anthropic API Error: OAuth token missing user:profile scope requirement
- [Bug] /usage command fails with OAuth token scope permission error
- Better 403 error messages
- [BUG] CLI is unrecoverable when returning to an expired session — /login and all inputs fail with 403
- [BUG] [Claude Desktop] Cowork VM agent sessions don't receive credentials (gateway mode or Bedrock direct mode)
- [BUG] Bedrock Application Inference Profile ARN SigV4 signing broken (claude-agent-sdk 0.2.93–0.2.96)
- [BUG] Dispatch returns 403 "Request not allowed" with Claude Max subscription
- [BUG] Issue logging into Claude Code in VS Code with Pro subscription
- [BUG] Asking for random login during session
- [Bug] Playwright Browser Download Blocked in Web Environment
- API Error: 403 The security token included in the request is invalid.
- headersHelper server falls into OAuth dynamic client registration on 401 instead of re-running the helper
- Your organization has disabled Claude subscription access for Claude Code · Use an Anthropic API key instead, or ask your admin to enable access
- [BUG] v1.8555 Breaks Cowork Causing 403 Expired Token on Authentication
- [BUG] Getting Please run /login · API Error: 403 on skill load when using with LiteLLM
- [BUG] Cowork returns 403 "Request not allowed" on Pro plan subscribed via iOS App Store
- [BUG] apiKeyHelper: 403 from expired token not retried — first prompt after idle always fails
- Windows Claude app Code mode: api.notion.com blocked by egress proxy (works on Mac)
- /voice fails on Windows: no SoX fallback when native audio module missing
- You've hit your limit · resets 7pm (Europe/Madrid)
- [BUG] Claude Desktop "Public Share" URLs return 403 when fetched by Claude Code
- [BUG] Step-up authorization not working for scope elevation in MCP TypeScript SDK
- [BUG] ECONNRESET on a fresh 2.1.39 install
- claude usage fails with scope error: token from setup-token lacks user:profile scope
- [BUG]: Authentication loop: Grey screen, 403 error, and claude command not found
- OAuth token revoked · Please run /login
- Frequent 403 "Request not allowed" errors despite Max subscription
- API Error: 403 {"error":{"type":"forbidden","message":"Request not allowed"}}