all docs
/ errors · HTTP 403 / 451

forbidden

ACE's own policy refusal — a dedicated deployment serving another tenant, a data-residency or geo-fence decision.

What it means

ACE's own policy refusal — a dedicated deployment serving another tenant, a data-residency or geo-fence decision.

How to recognise it

The gateway answers HTTP 403 / 451 with x-ace-error: forbidden on the response. This refusal has no typed envelope of its own, so the header is the reliable signal; the body is the surface's usual error shape.

Is it ACE or the provider?

x-ace-error is present only on errors ACE originated. A vendor error relayed from upstream — a real provider 429, a provider 401 for a bad pass-through key — carries no x-ace-error, and its own type and code mean what the provider says. Read the header before deciding whether to retry, re-mint a key or surface the error.