API Error 403 (permission_error) — page 2
The credential is valid but not allowed to use this model, org, or endpoint.
235 issues · 42 open · 193 resolved (82%) · first seen Feb 25, 2025
First response · account
What to do now
Most likely: The credential is valid but lacks access to the requested model, organization or policy scope.
- Confirm model availability and organization membership for the active account.
- Check enterprise policy or gateway allow-lists before rotating credentials.
- Capture the permission error body when asking an administrator for access.
These are conservative triage steps, not an official Anthropic fix. Use the issue and workaround evidence below before making a destructive configuration change.
Is this getting better or worse?
This class of problem is holding steady. 65 new reports in the last 90 days vs 75 in the 90 before — -13%. The open backlog peaked at 48 in 2026-07 and sits at 42 today.
Derived by counting each matching issue from its creation date until it closed. First-party
computation over the anthropics/claude-code tracker — the trend is not published
anywhere upstream.
Which builds report this
104 of these reports name the Claude Code build they were running, spanning 61 releases. Heaviest reporters:
- Claude Code v2.1.114
- Claude Code v2.1.220
- Claude Code v2.1.81
- Claude Code v2.1.211
- Claude Code v2.1.92
- Claude Code v2.1.195
- Claude Code v2.1.161
- Claude Code v2.1.12
Report volume, not a defect count: an issue can mention a build without that build having caused the failure. Versions come from the version string in the bug-report template, matched against real published tags.
Do these get fixed?
Median time to close is 14 days across 193 closures. Of the 193 closures with a recorded reason, 31% were closed as completed and 134 as not-planned or duplicate. The most recent completed fix landed in 2026-08.
Workarounds reported by the community
47 of these issues post a workaround someone says worked. The highest-engagement ones:
- [BUG]Cowork network egress allowlist not working - custom domains blocked with 403 blocked-by-allowlist
- …3. Proxy scope - Cowork might use a separate proxy instance Workaround: Run a local proxy bypass: export HTTP PROXY= Similar issues in OpenClaw's sandbox - config and enforcement must be synchronized.
Found in the thread of #30112 · still open - [Bug] Anthropic API Error: Usage credits required for 1M context window with opus-plan model
- …sn't work, and just stops working at 1M Context. A feasible workaround would be to periodically use the /compact command manually.
Found in the thread of #61869 · resolved - [BUG] Claude Code on the Web .NET SDK binary downloads blocked by proxy even with "All domains" network access enabled
- …SL -o /tmp/install.sh Returns: valid 1888-line shell script Workaround None currently. Users must: Have Claude write code Pull and compile locally Report errors back to Claude Repeat until code compiles This significantl…
Found in the description of #11897 · still open - [BUG] Bedrock: Claude Opus 4.7 returns permission_error despite AUTHORIZED entitlement status
- …resolution. I'd appreciate it if anyone could do the same. In the meantime, this doesn't seem to be a technical or configuration issue.
Found in the thread of #51183 · still open - [Bug] Anthropic API Error: OAuth token missing user:profile scope
- …completed successfully but error persists - Still getting: Workaround to try: Based on @gerrywastaken's comment, will try and logging back in instead of . Note: appears insufficient to fix this - requires full logout/lo…
Found in the thread of #11985 · still open
Excerpts are quoted from the linked issue so you can judge relevance before opening it. Threads that only ask for a workaround, or report that there is none, are excluded. These are community suggestions, not official guidance from Anthropic — read the full thread before applying one.
Matching issues 101–200
Ranked by community engagement (reactions weighted over comments).
- [BUG] Bedrock env vars ignored in home directory
- [BUG] API Error: 403 You don't have access to the model with the specified model ID. when operating with local files
- [BUG] Claude Code on the web: GitHub App has read-only access even though the same account has full write access from local Claude Code
- Auto-mode classifier repeatedly blocks browser navigation, persists after explicit user bypass / Exit Auto Mode
- [BUG] Resource not accessible by integration" 403, GitHub
- Cloud routines cannot access graph.facebook.com (Meta Ads API blocked by egress proxy)
- [BUG] "your organization has disabled claude subscription access for claude code usee an anthropic api key instead, or ask your admin to enable access"
- You've hit your session limit · resets 1:30pm (Asia/Calcutta)
- [Bug] Anthropic API Error: Rate limit - Server temporarily limiting requests
- [DOCS] Errors reference omits the "Your organization has disabled API key authentication" message and v2.1.169 guidance about which credential source to check
- [BUG] headersHelper output not applied to HTTP MCP requests -- SDK ignores tokens and falls through to OAuth 2.1 browser flow
- [BUG] Cowork — Additional allowed domains ignored on Team plan; same domain works on Pro plan
- [BUG] Cowork: 403 Request not allowed on every request — Pro plan
- [BUG]
- [BUG] Git push via local proxy returns HTTP 403, forcing GitHub-MCP fallback with content drift
- [Bug] MCP HTTP OAuth token exchange ignores authorization URL scopes, uses metadata instead
- [Bug] Anthropic API Error: 403 Forbidden on Cowork Session Registration
- CLI /login and /usage only see default (Max) org when account has multiple orgs
- [BUG] Claude deployed over ephemeral data without verifying backup, causing ~12 hours of processing and ~$50-100 in API costs lost
- [Bug] Image attachment causes unrecoverable "Could not process image" API 400 loop — context becomes unusable
- [BUG] 403 "Request not allowed" when creating new Cowork chat (existing chats work fine)
- [BUG] Cowork returns 403 "Request not allowed" on Pro plan — Chat and Code work fine, VPN global mode confirmed
- [Bug] /resume command lists sessions from all directories instead of current directory only
- [Bug] AWS Bedrock authentication failure with OIDC credentials in v2.1.96
- [BUG] v2.1.94 breaks Bedrock Bearer Token auth - "Authorization header is missing"
- Allowlist npm registry in Cowork sandbox to enable built-in slide-deck-designer skill
- [BUG] 403 issue
- [BUG] Cowork returns 403 on macOS 26.3.1 but works on macOS 26.3
- [BUG] Cowork 403 "Request not allowed" on Pro plan - macOS - account not enabled
- OAuth session silently invalidated: client_data returns empty, repeated /login prompts
- [BUG] Cowork scheduled task: domain api.asaas.com blocked by egress proxy (was working previously)
- [Feature Request] Support fetching claude.ai shared conversation links in Claude Code
- [BUG] can't access cowork while the chat and code functions are working well on my claude desktop
- Feature request: Claude Code should be able to read public Claude.ai shared conversations
- Cowork 403 'Request not allowed' error on Max plan - persists after cache clear and re-auth
- [BUG] [Cowork VM] npm install puppeteer fails with E403 Forbidden — Chromium post-install download likely blocked
- Cloudflare 403 blocks parallel subagent dispatch
- [BUG] Claude Code Max plan: Second concurrent session triggers Cloudflare 403 challenge instead of proper rate limit error
- [Bug] Anthropic API Error: 403 Cloudflare Challenge Block
- [BUG] Claude code cli OAuth token revoked after login
- [BUG] ext-apps viewer cannot fetch IIIF tiles despite correct CSP (regression ~Feb 26)
- [Bug] Long-lived token auth status unclear and usage tab broken with setup-token
- Auth: Frequent 403 'Request not allowed' requiring /login, persists after --resume
- [BUG] Failed to authenticate. API Error: 403 {"error":{"type":"forbidden","message":"Request not allowed"}}
- [FEATURE] Add npm.cloudsmith.io to allowed egress hosts for Claude Code Web
- [BUG] Infinite login in VS Code extension
- OAuth token missing user:profile scope - /usage fails on Linux
- setup-token missing user:profile scope — Usage tab in /status broken
- [BUG] Cowork VM network egress allowlist ignores Admin Capabilities settings
- [Bug] Anthropic API Error: 403 Edge IP Restricted from Cloudflare
- [BUG] OAuth token missing user:profile scope - prevents access to usage data and Claude Max features
- [Feature Request] Token usage refund policy for model training contributions
- [BUG] Code mode 403 error only with local folders (GitHub repos work fine) - Windows 11
- Can't view usage in claude code
- [Bug] Anthropic API Error: OAuth token missing user:profile scope for /usage command
- OAuth token revoked · Please run /login
- [BUG] Cannot access Gradle Servers due to Proxy in claude.ai/code in Full Access
- [Bug] Anthropic API Error: OAuth token missing user:profile scope for usage data
- [BUG] The command `/usage` return the error
- [BUG] Sessions freezing/hanging due to 400/403 API errors during session initialization
- [Bug] OAuth token insufficient scope: missing user:profile permission
- Responding to Claude, Better Prompts and Communication
- OAuth token revoked · Please run /login
- [Bug] Anthropic API Error: Pro Account Authentication Forbidden
- "/init" always returned "API Error: 403"
- [BUG] RESPONSE 403
- [BUG] API Error: Connection closed mid-response causes truncated/empty responses
- Pro subscription blocked in Claude Code — "organization has disabled subscription access" (unresolved after full re-auth + support escalation)
- git-credential-proxy failing for push operations (403) since 2026-07-24
- [BUG] Claude Code env "all domains" egress setting doesn't work
- [BUG] Cloud sessions: WebFetch surfaces egress-policy denials as bare 403s — and the allowlist blocks claude.com itself
- [Bug] Anthropic API Error: Server rate limiting on requests
- [BUG] Claude Code Plugin Directory Submission Link Redirects to Documentation URL and Returns 403 Forbidden
- [Bug] Anthropic API Error: Server Rate Limiting on Valid Requests
- [Bug] Claude Code auto-commits all uncommitted changes instead of only modified files
- [BUG] Personal Max account blocked from Claude Code - oauth_org_not_allowed (worked yesterday)
- [BUG] Network error
- Your organization has disabled Claude subscription access for Claude Code · Use an Anthropic API key instead, or ask your admin to enable access
- [DOCS] MCP docs omit combined startup notification for MCP server and connector authentication
- /stickers command returns 403 Forbidden on the linked sticker page
- I'm not able to generate a GitHub issue title from "resti" as it doesn't contain enough information about the bug or feature request. Could you please provide: - A description of the problem or feature request - Any error messages encountered - Steps to r
- [BUG] Please run /login · API Error: 403 {"error":{"type":"forbidden","message":"Request not allowed"}} /login Login OAuth error: Request failed with status code 403
- [DOCS] Troubleshooting docs omit server-error guidance and usage-vs-rate-limit distinction
- [BUG] Cowork 403 "Request not allowed" on Pro plan
- [Billing Bug] account_session_invalid on billing page – subscription paused 3 weeks
- [BUG] Claude Desktop - Google OAuth login loop, claude:// callback not delivered to running instance (Windows Store)
- [Bug] Unable to determine issue from empty bug report
- [FEATURE] ExpiredTokenException (403) from AWS Bedrock should fast-fail instead of retrying
- Settings usage page fails with OAuth scope error: permission_error user:profile
- [BUG] Error checking /usage
- [BUG] Claude Code Web: Proxy blocks CONNECT tunnel to npm.pkg.github.com (403), preventing yarn install of private packages
- Security: Claude Code exposed Figma API token in conversation by running 'claude mcp list'
- [Bug] /usage command fails with insufficient OAuth scope (user:profile required)
- [Bug] Anthropic API Error: OAuth token missing user:profile scope for /status usage data
- [BUG] <meta> tag in CLAUDE.md file causes 403 Forbidden error when using LiteLLM proxy
- [BUG] API Error: 403 when I successfully logged in using claude-code
- [BUG] Bedrock + `ANTHROPIC_MODEL` / inference profiles not being used for 3.5 Haiku requests
- [Bug] Atlassian MCP: 403 Forbidden on transitionJiraIssue and addCommentToJiraIssue
- [BUG] Claude Code on the web (cloud/remote sessions) can read but not push to my GitHub repo
- [BUG] headersHelper on http transport still falls into "Incompatible auth server: does not support dynamic client registration" on 2.1.211 (regression from #53267 persists)