ORIGIN_NOT_ALLOWED
The browser origin is not allowed for this route.
| HTTP status | 403 |
| Group | Platform |
| Retryable | No — sending it again changes nothing |
What happened
Cookie-authenticated routes accept a fixed set of origins.
What to do
Call the API from an allowed origin, or use a token instead of a cookie.
The problem document
Every error is application/problem+json (RFC 9457) with the same shape:
{
"type": "https://docs.co-relayer.com/errors/origin-not-allowed",
"title": "The browser origin is not allowed for this route.",
"status": 403,
"detail": "A sentence about this specific occurrence.",
"instance": "req_01JB…",
"code": "ORIGIN_NOT_ALLOWED",
"retryable": false,
"hint": "Call the API from an allowed origin, or use a token instead of a cookie."
}
See the error model for what each member means and how to handle unknown codes.