Guides ·

Claude Code 403 “Request not allowed” or region errors: what to check, in order

API Error: 403 Request not allowed means your request reached Anthropic and was refused. According to the official docs, the cause is one of four things: the wrong credential, your subscription or role, an unsupported region, or a proxy or firewall in the way. Run /status inside Claude Code first to see which credential is active, then check your plan, then your exit.

Claude Code 403: what to check, in orderPer the official docs, check four things in order: run /status and clear a stray ANTHROPIC_API_KEY; confirm your plan or Console role; check proxies and firewalls; then compare your exit region, since mainland China, Hong Kong and Macao are not supported. At a glance: fix a 403 in order 1 Run /status Clear any stray ANTHROPIC_API_KEY 2 Plan or role Pro / Max: plan active? Console: role? 3 Proxy or firewall Corporate proxies can interfere 4 Your terminal’s exit region Not supported: mainland China, HK, Macao Checked against Claude Code docs, Oct 5, 2026
Account first, exit second: a leftover API key in your shell overrides your subscription login.

Which error are you seeing?

Error strings and meanings below come from the Claude Code install and login troubleshooting guide and the error reference, checked on October 5, 2026.

Error textWhenCheck first
API Error: 403 Request not allowedAfter loginPlan, role, proxy
App unavailable in regionInstall script returns this pageRegion
curl: (22) The requested URL returned error: 403InstallRegion or proxy
API Error: 400 ... "This organization has been disabled"Active plan, still failsANTHROPIC_API_KEY
Please run /login · API Error: 401 Invalid authentication credentialsMid-session/status
Unable to connect to Anthropic servicesFirst-run setupNetwork, proxy, then region

Why do I get “403 Request not allowed” right after logging in?

The official “403 Forbidden after login” section lists three checks:

  1. Claude Pro / Max: confirm your subscription is active at claude.ai/settings.
  2. Claude Console (API) accounts: you need the “Claude Code” or “Developer” role. An admin assigns it under Settings → Members in the Console.
  3. Behind a proxy: corporate proxies can interfere with API requests. See network configuration.

If all three look fine, compare your exit region against the supported list below. The docs don’t say this message always means a region problem, so rule out the account side first.

I pay for Pro or Max. Why isn’t Claude Code using it?

Usually because an ANTHROPIC_API_KEY is still exported in your shell. Under the official authentication precedence, an approved API key wins over your /login subscription. The docs say this commonly happens when a key from a previous employer or project is still in a shell profile, and once that organization is disabled you get “This organization has been disabled” despite an active plan.

unset ANTHROPIC_API_KEY

Then remove the export ANTHROPIC_API_KEY=… line from ~/.zshrc, ~/.bashrc or ~/.profile and open a new terminal. On Windows, run Remove-Item Env:ANTHROPIC_API_KEY and check $PROFILE and your user environment variables. Confirm with /status. In non-interactive mode (claude -p) the key is always used when it’s set.

Which credential Claude Code usesWhen several credentials are present, ANTHROPIC_AUTH_TOKEN, ANTHROPIC_API_KEY, apiKeyHelper and CLAUDE_CODE_OAUTH_TOKEN all rank above the /login subscription, so a leftover API key overrides your plan. Which credential wins 1ANTHROPIC_AUTH_TOKEN 2ANTHROPIC_API_KEY Old keys linger here and override your plan 3apiKeyHelper 4CLAUDE_CODE_OAUTH_TOKEN 5/login subscription (default) /status shows which one is active Cloud provider and profile entries omitted; see docs
“Organization has been disabled” on an active plan usually means an old key at step 2 is in use.

Is a 403 during install a region block?

If the page says App unavailable in region, yes: the docs state Claude Code isn’t available in your country. A bare 403 with no body often has the same cause, but it can also be a corporate proxy or firewall blocking the download.

The docs’ connectivity test, run in the same shell you install from:

curl -sI https://downloads.claude.ai/claude-code-releases/latest

200 means you reached the server. 403 points to the two causes above. No output, Could not resolve host or a timeout means the network can’t connect at all, which is a different problem.

Which regions are not supported?

The source of truth is Anthropic’s supported countries and regions page. As of October 5, 2026, mainland China, Hong Kong and Macao are not listed; Taiwan, Japan, Singapore and the US are. The list changes, so check the page itself.

Keep in mind that Claude Code exits from your terminal, which isn’t always the same path as your browser. claude.ai working in the browser doesn’t prove the terminal uses the same exit. See why your terminal might bypass the proxy.

403 or “Unable to connect”?

A 403 means the request arrived and was refused. Unable to connect to API and its variants mean the connection never completed. They need different fixes.

403 vs. unable to connectA 403 means the request reached Anthropic and was refused: check credential, plan and region. Unable to connect means the connection never completed: check network, proxy, DNS and ANTHROPIC_BASE_URL. 403 vs. “Unable to connect” 403: arrived, then refused Terminal Network Refused Check credential, plan / role, region Unable to connect: never arrived Terminal Fails here Anthropic Check network, proxy, DNS, BASE_URL Same shell: curl -I https://api.anthropic.com
Refused and never-connected errors need different fixes, so tell them apart first.

Connection-failure messages in the error reference include:

  • Connection refused — a firewall or proxy may be blocking it (ConnectionRefused)
  • Can't reach the API server — check your internet or DNS (ENOTFOUND)
  • Couldn't connect through your proxy (ERR_PROXY_TUNNEL) (followed by more detail)
  • Request timed out. Check your internet connection and proxy settings

The docs suggest running curl -I https://api.anthropic.com from the same shell. Also check ANTHROPIC_BASE_URL: when it’s set, Claude Code sends requests there instead of api.anthropic.com, so a leftover value pointing at a stopped local gateway gives Connection refused even though curl works.

How do I see where Claude Code actually exits?

From the same terminal you run Claude Code in:

curl -sL ipjudge.org/en/cc | bash

The script applies Claude Code’s own proxy rules (only https_proxy and the three related variables, no SOCKS, no ALL_PROXY), asks api.anthropic.com which IP it sees, and compares that with claude.ai and your unproxied exit. It only reads; nothing is installed, changed or uploaded. Details on the Claude Code exit check page.

FAQ

Will running /login again fix a 403? Not if an API key is active. The docs note that /login doesn’t replace an approved ANTHROPIC_API_KEY; unset it first.

“Claude Code access has not been granted for this account”? Your Enterprise organization put you on a Custom role without Claude Code access. Nothing in Claude Code fixes it; an organization Owner has to grant access, then you log in again.

The browser works but the terminal gets 403. Is my account restricted? Not necessarily. Check that both use the same exit and the same credential first. A deactivated account usually shows a 401 or a disabled notice instead; see Claude account disabled.

I use Amazon Bedrock or Google Cloud and get 403. That 403 comes from the cloud provider, not Anthropic. The docs say it’s usually a missing IAM permission or a model not enabled for your account or region; fix it in the provider console.

Does a Hong Kong exit work? No. Hong Kong isn’t on the supported list, so a Hong Kong exit is treated as an unsupported region.

Anthropic’s terms expect you to use its services from a supported region. Accounts that get around the restriction from elsewhere may be limited or disabled.

Related: Claude Code exit check · Claude check · Terminal bypassing the proxy · Which IP ChatGPT and Claude see

Which kind of IP do you have?

Check my IP for free