# 403 response forbidden

**URL:** <https://forum.alpaca.markets/t/403-response-forbidden/5685>\
**Category:** Alpaca Trading\
**Created:** [May 12, 2021, 7:52pm UTC](https://forum.alpaca.markets/t/403-response-forbidden/5685 "2021-05-12T19:52:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Murali\_Radhakrishnan](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.alpaca.markets/murali_radhakrishnan/32/2218_2.png) [@Murali\_Radhakrishnan](https://forum.alpaca.markets/u/Murali_Radhakrishnan)\
**Post date:** [May 12, 2021, 7:52pm UTC](https://forum.alpaca.markets/t/403-response-forbidden/5685/1 "2021-05-12T19:52:20Z")

</div>

403 response forbidden  
json\_dump = r.json()  
\<Response [403]\>  
{‘message’: ‘forbidden.’}

Still getting this error in my paper trading account. Please help me to resolve this issue. I tried it in both V1 and V2 end points.  
endpoint = “[https://data.alpaca.markets/v1](https://data.alpaca.markets/v1)”  
endpoint = “[https://data.alpaca.markets/v2](https://data.alpaca.markets/v2)”

---

<div class="post-metadata">

**Author:** ![Dan\_Whitnable\_Alpaca](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.alpaca.markets/dan_whitnable_alpaca/32/1658_2.png) [@Dan\_Whitnable\_Alpaca](https://forum.alpaca.markets/u/Dan_Whitnable_Alpaca)\
**Post date:** [May 13, 2021, 2:44pm UTC](https://forum.alpaca.markets/t/403-response-forbidden/5685/2 "2021-05-13T14:44:24Z")

</div>

One needs to call the entire URL and not just the base URL (ie [https://data.alpaca.markets/v1](https://data.alpaca.markets/v1) and [https://data.alpaca.markets/v2](https://data.alpaca.markets/v2) won’t work). Maybe you have already tried and the above was just an example? The following will work to get the latest trades for AAPL (note you need to include your own API key and Secret key as headers)

```
GET https://data.alpaca.markets/v2/stocks/AAPL/trades/latest
APCA-API-KEY-ID: XXXXXXX
APCA-API-SECRET-KEY: XXXXXXX
```

---

<div class="post-metadata">

**Author:** ![meteor](https://avatars.discourse-cdn.com/v4/letter/m/839c29/32.png) [@meteor](https://forum.alpaca.markets/u/meteor)\
**Post date:** [May 31, 2021, 9:06am UTC](https://forum.alpaca.markets/t/403-response-forbidden/5685/3 "2021-05-31T09:06:17Z")

</div>

Hi Dan,

could you suggest some solution for the following issue.  
i am trying windows 64 bit, python 3.6.6, Zipline -trader.

alpaca:  
key\_id: “\<_**\>"  
secret: "\<**_\>”  
base\_url: [https://paper-api.alpaca.markets](https://paper-api.alpaca.markets)  
custom\_asset\_list: AAPL, TSLA, GOOG

.HTTPError: 403 Client Error: Forbidden for url: [https://data.alpaca.markets/v1/bars/day?symbols=TSLA%2CAAPL%2CGOOG&limit=1000&end=2021-05-28T00%3A00%3A00%2B00%3A00](https://data.alpaca.markets/v1/bars/day?symbols=TSLA%2CAAPL%2CGOOG&limit=1000&end=2021-05-28T00%3A00%3A00%2B00%3A00)

---

<div class="post-metadata">

**Author:** ![algorithmatic](https://avatars.discourse-cdn.com/v4/letter/a/eada6e/32.png) [@algorithmatic](https://forum.alpaca.markets/u/algorithmatic)\
**Post date:** [November 15, 2021, 1:22am UTC](https://forum.alpaca.markets/t/403-response-forbidden/5685/4 "2021-11-15T01:22:11Z")

</div>

Hi Dan,  
Can you help me understand that when I put what you have outlined in your May 13, 2021 post in Postman with both paper and live keys I get {‘message’: ‘forbidden.’} for both.  
This was working in July 2021 but not in November 2021.  
Has something changed?  
If so, what changed and is there a resolution?

---

<div class="post-metadata">

**Author:** ![muhe](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.alpaca.markets/muhe/32/1493_2.png) [@muhe](https://forum.alpaca.markets/u/muhe)\
**Post date:** [November 25, 2021, 3:04pm UTC](https://forum.alpaca.markets/t/403-response-forbidden/5685/5 "2021-11-25T15:04:52Z")

</div>

Thank you this helped. I mainly had to make sure the initialization was correct.
