# origin_refused

Source: https://capacms.com/docs/errors/origin_refused

403 permission. The key is restricted to other origins than the one this request came from.

| HTTP status | `type`       | Surfaces      |
| ----------- | ------------ | ------------- |
| 403         | `permission` | REST, GraphQL |

## What it means

The key is restricted to other origins than the one this request came from.

| When                                                     | What the `hint` tells you                                                                                                           |
| -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| the key is bound to origins and this `Origin` is not one | no hint on REST; the message names the refused origin. Add it to the key under Developers > Keys, or send the request from a server |

## What to do

Call from an allowed origin, or use a key without an origin list for server-side reads.

## On GraphQL

`/api/graphql` answers the same `code` inside `errors[].extensions`. The status depends on the `Accept` header you send ([status codes](https://capacms.com/docs/api/graphql#status-codes)):

| `application/json` | `graphql-response+json` | When                                                        |
| ------------------ | ----------------------- | ----------------------------------------------------------- |
| 403                | 403                     | the key's origin rules or the edge lock refused the request |

## See also

* [Keys and scopes](https://capacms.com/docs/api/authentication)
