# HTTP Status Forbidden from Paper API Server

**URL:** <https://forum.alpaca.markets/t/http-status-forbidden-from-paper-api-server/13878>\
**Category:** Alpaca Account Troubleshooting\
**Created:** [March 18, 2024, 2:57pm UTC](https://forum.alpaca.markets/t/http-status-forbidden-from-paper-api-server/13878 "2024-03-18T14:57:47Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![trevdawg122](https://avatars.discourse-cdn.com/v4/letter/t/6f9a4e/32.png) [@trevdawg122](https://forum.alpaca.markets/u/trevdawg122)\
**Post date:** [March 18, 2024, 2:57pm UTC](https://forum.alpaca.markets/t/http-status-forbidden-from-paper-api-server/13878/1 "2024-03-18T14:57:47Z")

</div>

Hello. My REST calls for account info are getting a forbidden HTTP 403 response. I tried checking with the curl command at [Authentication](https://docs.alpaca.markets/docs/authentication-1) but it’s also forbidden. I’m trying to access [https://paper-api.alpaca.markets/v2/account](https://paper-api.alpaca.markets/v2/account)

I tried regenerating my API keys but it didn’t help. Any ideas? I’ve looked at a lot of the ‘similar to’ topics but none have had the answer.

---

<div class="post-metadata">

**Author:** ![Andy\_S](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.alpaca.markets/andy_s/32/5686_2.png) [@Andy\_S](https://forum.alpaca.markets/u/Andy_S)\
**Post date:** [March 18, 2024, 4:30pm UTC](https://forum.alpaca.markets/t/http-status-forbidden-from-paper-api-server/13878/2 "2024-03-18T16:30:00Z")

</div>

Are you using algo to access your account ?

---

<div class="post-metadata">

**Author:** ![Dan\_Whitnable\_Alpaca](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.alpaca.markets/dan_whitnable_alpaca/32/1658_2.png) [@Dan\_Whitnable\_Alpaca](https://forum.alpaca.markets/u/Dan_Whitnable_Alpaca)\
**Post date:** [March 18, 2024, 4:53pm UTC](https://forum.alpaca.markets/t/http-status-forbidden-from-paper-api-server/13878/3 "2024-03-18T16:53:52Z")

</div>

@trevdawg122 Try the following request. It fetches account info for a demo account. If you can get that to respond, then replace the API key and secret key with your own paper account keys. That should then return info for your account. If you get a forbidden error then either your key or secret key are incorrect.

```auto
curl --location 'https://paper-api.alpaca.markets/v2/account' \
--header 'APCA-API-KEY-ID: PKZ4HPYI4PMMCXZ4XEIS' \
--header 'APCA-API-SECRET-KEY: J3sV2W1nGK4PchSxb2jR1g5daSovyFcqLbgAABxB'

```

Does that help?

---

<div class="post-metadata">

**Author:** ![trevdawg122](https://avatars.discourse-cdn.com/v4/letter/t/6f9a4e/32.png) [@trevdawg122](https://forum.alpaca.markets/u/trevdawg122)\
**Post date:** [March 18, 2024, 6:41pm UTC](https://forum.alpaca.markets/t/http-status-forbidden-from-paper-api-server/13878/4 "2024-03-18T18:41:04Z")

</div>

It’s a python script using the alpaca\_trade\_api library.

---

<div class="post-metadata">

**Author:** ![trevdawg122](https://avatars.discourse-cdn.com/v4/letter/t/6f9a4e/32.png) [@trevdawg122](https://forum.alpaca.markets/u/trevdawg122)\
**Post date:** [March 18, 2024, 6:45pm UTC](https://forum.alpaca.markets/t/http-status-forbidden-from-paper-api-server/13878/5 "2024-03-18T18:45:04Z")

</div>

@Dan_Whitnable_Alpaca, that does help. I tried your curl command syntax for the demo account and my account and they both returned successful request responses. I then tried my original script and it worked as well. I’m not sure what happened so it’s probably safe to say I got confused. The example from the page I shared earlier, [Authentication](https://docs.alpaca.markets/docs/authentication-1), still doesn’t work and that didn’t help my confusion.

Thanks for helping me troubleshoot!

---

<div class="post-metadata">

**Author:** ![trevdawg122](https://avatars.discourse-cdn.com/v4/letter/t/6f9a4e/32.png) [@trevdawg122](https://forum.alpaca.markets/u/trevdawg122)\
**Post date:** [March 19, 2024, 3:08am UTC](https://forum.alpaca.markets/t/http-status-forbidden-from-paper-api-server/13878/6 "2024-03-19T03:08:47Z")

</div>

@Dan_Whitnable_Alpaca , I found out what was going on. I reset my account thinking it was only resetting my portfolio. With that knowledge I now see this has confused others in the past and you suggested fixing it. See below. Thanks again.

> [@Paper trading API key changes with reset](https://forum.alpaca.markets/t/paper-trading-api-key-changes-with-reset/939):
>
> Questions if you could help: Is there any way to not have the API key and secret key change when you reset the amount in your paper trading account? I would like them to stay the same after reset so I do not need to chnge them in the remote server I am using to trade against the alpaca api. THX GF

> <https://github.com/alpacahq/Alpaca-API/issues/151>
>
> Currently, when a paper trading account is reset it also resets the API\_KEY and …the SECRET\_KEY. This creates confusion, and a fair amount of support issues, because user trading programs then fail with the wrong key.
> 
> One solution would be to copy the key and secret key to the new account. If this is not possible, perhaps at least add a message indicating that the keys must be updated after an account reset.

---

<div class="post-metadata">

**Author:** ![altagraciareta](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.alpaca.markets/altagraciareta/32/5918_2.png) [@altagraciareta](https://forum.alpaca.markets/u/altagraciareta)\
**Post date:** [March 19, 2024, 1:28pm UTC](https://forum.alpaca.markets/t/http-status-forbidden-from-paper-api-server/13878/7 "2024-03-19T13:28:33Z")

</div>

I am facing this issue also.

---

<div class="post-metadata">

**Author:** ![Dan\_Whitnable\_Alpaca](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.alpaca.markets/dan_whitnable_alpaca/32/1658_2.png) [@Dan\_Whitnable\_Alpaca](https://forum.alpaca.markets/u/Dan_Whitnable_Alpaca)\
**Post date:** [March 19, 2024, 1:36pm UTC](https://forum.alpaca.markets/t/http-status-forbidden-from-paper-api-server/13878/8 "2024-03-19T13:36:23Z")

</div>

@trevdawg122 I can certainly relate to the issues/frustrations with having the API keys reset when resetting a paper account. This behavior, however is not going to change anytime soon. It may help to understand that resetting an account doesn’t simply ‘reset’ the various values. In the background, an entirely new account is created. The old account isn’t really deleted. Actually, you can still access the orders etc from an old account by using the old API keys (which also can create some confusion).

---

<div class="post-metadata">

**Author:** ![trevdawg122](https://avatars.discourse-cdn.com/v4/letter/t/6f9a4e/32.png) [@trevdawg122](https://forum.alpaca.markets/u/trevdawg122)\
**Post date:** [March 20, 2024, 3:01pm UTC](https://forum.alpaca.markets/t/http-status-forbidden-from-paper-api-server/13878/9 "2024-03-20T15:01:06Z")

</div>

@Dan_Whitnable_Alpaca it’s not a big problem since I’m aware and assuming I don’t forget again! How about something to notify the user in the UI that if they reset they’ll also need new keys to access the account info?

---

<div class="post-metadata">

**Author:** ![Dan\_Whitnable\_Alpaca](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.alpaca.markets/dan_whitnable_alpaca/32/1658_2.png) [@Dan\_Whitnable\_Alpaca](https://forum.alpaca.markets/u/Dan_Whitnable_Alpaca)\
**Post date:** [March 20, 2024, 3:08pm UTC](https://forum.alpaca.markets/t/http-status-forbidden-from-paper-api-server/13878/10 "2024-03-20T15:08:55Z")

</div>

@trevdawg122 Good callout. I’ll pass it on to the UI team that a notification may needed when resetting an account.
