# edge_only

Source: https://capacms.com/docs/errors/edge_only

403 permission. The request reached the origin directly.

| HTTP status | `type`       | Surfaces      |
| ----------- | ------------ | ------------- |
| 403         | `permission` | REST, GraphQL |

## What it means

The request reached the origin directly. `/api/` answers only through Capa's CDN.

| When                                                               | What the `hint` tells you   |
| ------------------------------------------------------------------ | --------------------------- |
| the request reached the origin directly instead of through the CDN | send it to the API hostname |

## What to do

Send the request to `https://cdn.capacms.com`, the API's public host, not to an origin address.

## The response

HTTP 403:

```json
{
  "error": {
    "type": "permission",
    "code": "edge_only",
    "message": "Direct origin access is not allowed. Request this through the CDN hostname.",
    "docs": "https://docs.capacms.com/errors/edge_only"
  },
  "meta": {
    "version": "2026-10-01",
    "contract": 1,
    "requestId": "req_0f3c…"
  }
}
```

## On GraphQL

`/api/graphql` answers the same `code` inside `errors[].extensions`. The status depends on the `Accept` header you send ([status codes](https://capacms.com/docs/api/graphql#status-codes)):

| `application/json` | `graphql-response+json` | When                                                        |
| ------------------ | ----------------------- | ----------------------------------------------------------- |
| 403                | 403                     | the key's origin rules or the edge lock refused the request |

## See also

* [API reference](https://capacms.com/docs/api)
