Error reference

forbidden

HTTP status
403 Forbidden
Returned by
API keys; Every endpoint (request handling); Integrations; Members and invites; OAuth for apps; Every endpoint (permissions); savedreply; Kweko Admin (staff only, not the public API); Webhooks

What it means

The caller is authenticated but is not allowed to do this. For API keys and apps it usually means the key lacks the scope for this action. permission names the permission that was checked.

Typical causes

  • The API key or app does not have the scope for the action, for example leads:write to change a lead.
  • The action is only for owners and admins signed in to Kweko (some settings endpoints).
  • For a member session: the member's role does not allow it.

How to fix it

  • Check the endpoint's scope in the API reference and add it to the key (create a new key with the scope, since scopes are fixed per key), or ask the workspace to grant it to your app.
  • The permission value maps to a scope: leads.view needs leads:read, other leads.* actions need leads:write. See Scopes.

Messages

English text, as sent with Accept-Language: en. With ru or uz the API sends the translation.

  • Only an owner can change another owner.
    RU: Изменить владельца может только другой владелец.
    UZ: Egani faqat boshqa ega oʻzgartira oladi.
  • Only members who can export records and see full contact data can sync to Google Sheets.
    RU: Синхронизировать с Google Таблицами могут только сотрудники, которым разрешён экспорт и видны полные контакты.
    UZ: Google Sheets bilan faqat eksportga ruxsati bor va kontaktlarni toʻliq koʻradigan xodimlar sinxronlay oladi.
  • Only owners and admins can install apps.
    RU: Устанавливать приложения могут только владельцы и администраторы.
    UZ: Ilovalarni faqat egalar va administratorlar oʻrnata oladi.
  • Only owners and admins can manage API keys.
    RU: Управлять API-ключами могут только владельцы и администраторы.
    UZ: API kalitlarni faqat egalar va administratorlar boshqara oladi.
  • Only owners and admins can manage webhooks.
    RU: Управлять вебхуками могут только владельцы и администраторы.
    UZ: Webhooklarni faqat egalar va administratorlar boshqara oladi.
  • Personal replies belong to a member. Save a shared reply instead.
    RU: Личные ответы принадлежат участнику. Сохраните общий ответ.
    UZ: Shaxsiy javoblar aʼzoga tegishli. Buning oʻrniga umumiy javob saqlang.
  • You don't have permission to do this.
    RU: У вас нет прав на это действие.
    UZ: Bu amal uchun sizda ruxsat yoʻq.
  • Your staff role cannot do this.
    RU: Ваша роль сотрудника не позволяет это сделать.
    UZ: Xodim rolingiz bunga ruxsat bermaydi.

Example response

Response
HTTP/1.1 403 Forbidden
Content-Type: application/json; charset=utf-8
X-Request-Id: req_4f2a9c1e0b7d3a55

{
  "error": {
    "code": "forbidden",
    "message": "You don't have permission to do this.",
    "request_id": "req_4f2a9c1e0b7d3a55",
    "docs_url": "https://developers.kweko.uz/errors/forbidden",
    "permission": "leads.edit"
  }
}

All error codes · The error format