Error reference

permission_denied

HTTP status
403 Forbidden
Returned by
API keys; Webhooks

What it means

This action is reserved for people signed in to Kweko: an API key or app cannot do it even with every scope.

Typical causes

  • Managing API keys (/v1/api-keys, except whoami) with an API key.
  • Revealing a webhook signing secret with an API key.

How to fix it

  • Do it in Kweko: Settings → Developers. Webhook secrets are shown once on creation and on rotation (POST /v1/webhooks/{id}/rotate-secret).

Messages

English text, as sent with Accept-Language: en. With ru or uz the API sends the translation.

  • API keys can be managed only by workspace owners and admins in Kweko.
    RU: Управлять API-ключами могут только владельцы и администраторы пространства в Kweko.
    UZ: API kalitlarni faqat ish joyi egalari va administratorlar Kweko ichida boshqara oladi.
  • Signing secrets can be revealed only in Kweko.
    RU: Секрет подписи можно посмотреть только в Kweko.
    UZ: Imzo kalitini faqat Kweko ichida koʻrish mumkin.

Example response

Response
HTTP/1.1 403 Forbidden
Content-Type: application/json; charset=utf-8
X-Request-Id: req_4f2a9c1e0b7d3a55

{
  "error": {
    "code": "permission_denied",
    "message": "API keys can be managed only by workspace owners and admins in Kweko.",
    "request_id": "req_4f2a9c1e0b7d3a55",
    "docs_url": "https://developers.kweko.uz/errors/permission_denied"
  }
}

All error codes · The error format