Docs

edge_only

403 permission. The request reached the origin directly.

View as Markdown
HTTP statustypeSurfaces
403permissionREST, GraphQL

What it means

The request reached the origin directly. /api/ answers only through Capa's CDN.

WhenWhat the hint tells you
the request reached the origin directly instead of through the CDNsend it to the API hostname

What to do

Send the request to https://cdn.capacms.com, the API's public host, not to an origin address.

The response

HTTP 403:

{
  "error": {
    "type": "permission",
    "code": "edge_only",
    "message": "Direct origin access is not allowed. Request this through the CDN hostname.",
    "docs": "https://docs.capacms.com/errors/edge_only"
  },
  "meta": {
    "version": "2026-10-01",
    "contract": 1,
    "requestId": "req_0f3c…"
  }
}

On GraphQL

/api/graphql answers the same code inside errors[].extensions. The status depends on the Accept header you send (status codes):

application/jsongraphql-response+jsonWhen
403403the key's origin rules or the edge lock refused the request

See also