<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic API Returns 403 for some but not all endpoints in cybersource APIs</title>
    <link>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/86374#M903</link>
    <description>&lt;P&gt;Hi, I'm using a sandbox environment and I'm trying to generate a payment using an existing token, but am getting a 403 error.&amp;nbsp; I tried the following things.&lt;/P&gt;&lt;P&gt;First, I have generated a REST Shared Secret key, and using both HTTP Signature as well as a p12 certificate, my calls to&amp;nbsp;&lt;A href="https://developer.cybersource.com/api-reference-assets/index.html#transaction-search_search-transactions_create-a-search-request" target="_blank"&gt;https://developer.cybersource.com/api-reference-assets/index.html#transaction-search_search-transactions_create-a-search-request&lt;/A&gt;&amp;nbsp;seem to work either way.&amp;nbsp; I've even been able to generate payments with a credit card.&lt;/P&gt;&lt;P&gt;I manually generated a subscription within the ebc2test admin UI.&amp;nbsp; No issues... it gives me a valid customer number to work with, does the charges correctly, etc.&lt;/P&gt;&lt;P&gt;Now to the API endpoints I may want to use.&amp;nbsp; I decided to start with a simple "Get a subscription"&amp;nbsp;&lt;A href="https://developer.cybersource.com/api-reference-assets/index.html#recurring-billing-subscriptions_subscriptions_get-a-subscription" target="_blank"&gt;https://developer.cybersource.com/api-reference-assets/index.html#recurring-billing-subscriptions_subscriptions_get-a-subscription&lt;/A&gt;&amp;nbsp;since nothing else seemed to be working.&amp;nbsp; I changed the parameter correctly to have the correct subscription number i.e.&amp;nbsp;&lt;A href="https://apitest.cybersource.com/rbs/v1/subscriptions/6XXXXXXXXXXXXXXXXXXXX2" target="_blank"&gt;https://apitest.cybersource.com/rbs/v1/subscriptions/6XXXXXXXXXXXXXXXXXXXX2&lt;/A&gt;&amp;nbsp;(obscured here) and I get the following response:&lt;/P&gt;&lt;P&gt;{&lt;BR /&gt;"submitTimeUtc": "2023-04-30T06:17:25.755Z",&lt;BR /&gt;"status": "FORBIDDEN",&lt;BR /&gt;"reason": "INVALID_DATA",&lt;BR /&gt;"message": "Authorization Failure!",&lt;BR /&gt;"details": []&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;What I don't get is why some endpoints seem to get a 403 and some don't with the exact same values for authorization.&amp;nbsp; Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 30 Apr 2023 06:19:06 GMT</pubDate>
    <dc:creator>jnorman</dc:creator>
    <dc:date>2023-04-30T06:19:06Z</dc:date>
    <item>
      <title>API Returns 403 for some but not all endpoints</title>
      <link>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/86374#M903</link>
      <description>&lt;P&gt;Hi, I'm using a sandbox environment and I'm trying to generate a payment using an existing token, but am getting a 403 error.&amp;nbsp; I tried the following things.&lt;/P&gt;&lt;P&gt;First, I have generated a REST Shared Secret key, and using both HTTP Signature as well as a p12 certificate, my calls to&amp;nbsp;&lt;A href="https://developer.cybersource.com/api-reference-assets/index.html#transaction-search_search-transactions_create-a-search-request" target="_blank"&gt;https://developer.cybersource.com/api-reference-assets/index.html#transaction-search_search-transactions_create-a-search-request&lt;/A&gt;&amp;nbsp;seem to work either way.&amp;nbsp; I've even been able to generate payments with a credit card.&lt;/P&gt;&lt;P&gt;I manually generated a subscription within the ebc2test admin UI.&amp;nbsp; No issues... it gives me a valid customer number to work with, does the charges correctly, etc.&lt;/P&gt;&lt;P&gt;Now to the API endpoints I may want to use.&amp;nbsp; I decided to start with a simple "Get a subscription"&amp;nbsp;&lt;A href="https://developer.cybersource.com/api-reference-assets/index.html#recurring-billing-subscriptions_subscriptions_get-a-subscription" target="_blank"&gt;https://developer.cybersource.com/api-reference-assets/index.html#recurring-billing-subscriptions_subscriptions_get-a-subscription&lt;/A&gt;&amp;nbsp;since nothing else seemed to be working.&amp;nbsp; I changed the parameter correctly to have the correct subscription number i.e.&amp;nbsp;&lt;A href="https://apitest.cybersource.com/rbs/v1/subscriptions/6XXXXXXXXXXXXXXXXXXXX2" target="_blank"&gt;https://apitest.cybersource.com/rbs/v1/subscriptions/6XXXXXXXXXXXXXXXXXXXX2&lt;/A&gt;&amp;nbsp;(obscured here) and I get the following response:&lt;/P&gt;&lt;P&gt;{&lt;BR /&gt;"submitTimeUtc": "2023-04-30T06:17:25.755Z",&lt;BR /&gt;"status": "FORBIDDEN",&lt;BR /&gt;"reason": "INVALID_DATA",&lt;BR /&gt;"message": "Authorization Failure!",&lt;BR /&gt;"details": []&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;What I don't get is why some endpoints seem to get a 403 and some don't with the exact same values for authorization.&amp;nbsp; Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Apr 2023 06:19:06 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/86374#M903</guid>
      <dc:creator>jnorman</dc:creator>
      <dc:date>2023-04-30T06:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: API Returns 403 for some but not all endpoints</title>
      <link>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/86447#M922</link>
      <description>&lt;P&gt;For anyone following this thread, I have emailed their developer support using this form&amp;nbsp;&lt;A href="https://developer.cybersource.com/support/contact-us.html" target="_blank"&gt;https://developer.cybersource.com/support/contact-us.html&lt;/A&gt;&amp;nbsp;and will post a follow-up presuming something useful comes back from them.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 19:33:33 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/86447#M922</guid>
      <dc:creator>jnorman</dc:creator>
      <dc:date>2023-05-09T19:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: API Returns 403 for some but not all endpoints</title>
      <link>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/86907#M1007</link>
      <description>&lt;P&gt;Hey there, did you ever get a response from them? I am having the same issue right now. New key that will not work. This was the response I got:&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"submitTimeUtc"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"2023-06-28T16:57:28.902Z"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"status"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"FORBIDDEN"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"reason"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"INVALID_DATA"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"message"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"Authorization Failure!"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;I noticed it is specifically an authorization failure instead of an authentication failure. I did not see anywhere in the business center portal that would leave me to believe the key was a limited-rights key of any kind.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 28 Jun 2023 17:21:51 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/86907#M1007</guid>
      <dc:creator>FCDev</dc:creator>
      <dc:date>2023-06-28T17:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: API Returns 403 for some but not all endpoints</title>
      <link>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/86926#M1015</link>
      <description>&lt;P&gt;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/64499"&gt;@jnorman&lt;/a&gt;&amp;nbsp;: Were you able to create a Customer Token or a subscription :&lt;/P&gt;
&lt;P&gt;"I manually generated a subscription within the ebc2test admin UI. No issues... it gives me a valid customer number to work with, does the charges correctly, etc. ?"&lt;BR /&gt;&lt;BR /&gt;For Cybersource, the 2 entities are different. Customer token is created to identify a customer.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Subscription is a way to periodically charge a customer for recurring charges.&lt;/P&gt;
&lt;P&gt;What is the use case you are trying to accomplish ? That should help us guide you in the correct direction.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 21:32:06 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/86926#M1015</guid>
      <dc:creator>rajvpate</dc:creator>
      <dc:date>2023-07-03T21:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: API Returns 403 for some but not all endpoints</title>
      <link>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/87280#M1113</link>
      <description>&lt;P&gt;The solution turned out to be a combination of things.&lt;/P&gt;&lt;P&gt;First look at&amp;nbsp;\Samples\Authentication\StandAloneHttpSignature.cs&lt;/P&gt;&lt;P&gt;&amp;nbsp;Look at LegacyToken_id , uri to post&amp;nbsp;pts/v2/payments&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 18:42:53 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/87280#M1113</guid>
      <dc:creator>jnorman</dc:creator>
      <dc:date>2023-08-08T18:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: API Returns 403 for some but not all endpoints</title>
      <link>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/87281#M1114</link>
      <description>&lt;P&gt;&lt;SPAN&gt;\Samples\Authentication\StandAloneHttpSignature.cs is what I based my authentication on as well, and it worked on sandbox no issue&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For me, the issue was because the development sandbox environment supported all operations and endpoints that I personally tested, but the live environment did NOT support certain endpoints for some reason. It just threw the FORBIDDEN. None of the documentation even stated that it was limited, or certain portions of Secure Acceptance was not going to be used (then why make it and all the docs neglect to mention this?).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I ended up going through the Simple Order system and the endpoints there supported my desired operations.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 18:49:17 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/87281#M1114</guid>
      <dc:creator>FCDev</dc:creator>
      <dc:date>2023-08-08T18:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: API Returns 403 for some but not all endpoints</title>
      <link>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/87282#M1115</link>
      <description>&lt;P&gt;That is very interesting to me.&amp;nbsp; Thank you, and sorry it took so long to revisit.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 18:51:33 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/87282#M1115</guid>
      <dc:creator>jnorman</dc:creator>
      <dc:date>2023-08-08T18:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: API Returns 403 for some but not all endpoints</title>
      <link>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/95020#M4147</link>
      <description>&lt;P&gt;This looks like a permission or access issue on some endpoints. Maybe your API key or user role is not allowed to &lt;SPAN&gt;&lt;A href="https://furnifolks.uk/" target="_blank" rel="noopener"&gt;furni folks&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;those requests. Check your auth settings and endpoint rules to fix the 403 error.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2026 11:57:13 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/cybersource-APIs/API-Returns-403-for-some-but-not-all-endpoints/m-p/95020#M4147</guid>
      <dc:creator>jackwilliam78</dc:creator>
      <dc:date>2026-03-26T11:57:13Z</dc:date>
    </item>
  </channel>
</rss>

