Skip to main content

ORIGIN_NOT_ALLOWED

The browser origin is not allowed for this route.

HTTP status403
GroupPlatform
RetryableNo — sending it again changes nothing

What happened​

Cookie-authenticated routes accept a fixed set of origins.

What to do​

Call the API from an allowed origin, or use a token instead of a cookie.

The problem document​

Every error is application/problem+json (RFC 9457) with the same shape:

{
"type": "https://docs.co-relayer.com/errors/origin-not-allowed",
"title": "The browser origin is not allowed for this route.",
"status": 403,
"detail": "A sentence about this specific occurrence.",
"instance": "req_01JB…",
"code": "ORIGIN_NOT_ALLOWED",
"retryable": false,
"hint": "Call the API from an allowed origin, or use a token instead of a cookie."
}

See the error model for what each member means and how to handle unknown codes.