all docs
/ errors · HTTP 403

upstream_not_allowed

The upstream host the caller named is not a public https host.

What it means

The upstream the caller named — x-ace--base-url or -endpoint, x-ace-base-url, a region that builds a host — or the endpoint stored on the vendor key is not a public https host: plain http, or a host that resolves to a private, loopback, link-local, CGNAT (100.64/10), unique-local IPv6, multicast, unspecified or cloud-metadata address, IPv4-mapped and other IPv6 spellings included. Nothing was sent upstream. ACE connects to the address it checked, so a DNS answer that changes in between cannot redirect the call. The operator's own base-URL settings and the vendors' default hosts are not checked. Fix the URL, or, on-prem, list the internal host in ACE_UPSTREAM_ALLOW_HOSTS (host names, .suffix patterns, IPs or CIDRs; a listed name may also be plain http).

How to recognise it

The gateway answers HTTP 403 with x-ace-error: upstream_not_allowed on the response, and a body in the shared error envelope:

{
  "error": {
    "message": "...",
    "type": "upstream_not_allowed",
    "code": 403
  }
}

On a vendor-shaped surface (/anthropic/…, /gemini/…, /bedrock/…) the body wears that vendor's error envelope instead; the x-ace-error header is the same everywhere.

Is it ACE or the provider?

x-ace-error is present only on errors ACE originated. A vendor error relayed from upstream — a real provider 429, a provider 401 for a bad pass-through key — carries no x-ace-error, and its own type and code mean what the provider says. Read the header before deciding whether to retry, re-mint a key or surface the error.

Other 403 errors

  • model_not_in_scope: Requested model is not enabled for this tenant.
  • invalid_admin_key: Admin-only endpoint called with a non-admin key.
  • skill_locked: A per-request skill override (skill_overrides or x-ace-skills) on a skill the org has locked.
  • idp_forbidden_error: A deployment fronted by a corporate identity provider accepted the caller's IdP token but its group mapping grants no access.