permission_denied
- HTTP status
- 403 Forbidden
- Returned by
- API keys; Webhooks
What it means
This action is reserved for people signed in to Kweko: an API key or app cannot do it even with every scope.
Typical causes
- Managing API keys (
/v1/api-keys, exceptwhoami) with an API key. - Revealing a webhook signing secret with an API key.
How to fix it
- Do it in Kweko: Settings → Developers. Webhook secrets are shown once on creation and on rotation (
POST /v1/webhooks/{id}/rotate-secret).
Messages
English text, as sent with Accept-Language: en. With ru or uz the API sends the translation.
- API keys can be managed only by workspace owners and admins in Kweko.
RU: Управлять API-ключами могут только владельцы и администраторы пространства в Kweko.
UZ: API kalitlarni faqat ish joyi egalari va administratorlar Kweko ichida boshqara oladi. - Signing secrets can be revealed only in Kweko.
RU: Секрет подписи можно посмотреть только в Kweko.
UZ: Imzo kalitini faqat Kweko ichida koʻrish mumkin.
Example response
Response
HTTP/1.1 403 Forbidden
Content-Type: application/json; charset=utf-8
X-Request-Id: req_4f2a9c1e0b7d3a55
{
"error": {
"code": "permission_denied",
"message": "API keys can be managed only by workspace owners and admins in Kweko.",
"request_id": "req_4f2a9c1e0b7d3a55",
"docs_url": "https://developers.kweko.uz/errors/permission_denied"
}
}