Cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

403 Forbidden on OAuth authorize - Personal app blocked

Hello,

I am consistently receiving a 403 Forbidden error when trying to access the authorization URL for my Personal applications.

My Client IDs: 23TQJH and 23TLHX (tried both, same error)

The URL that returns 403:
https://www.fitbit.com/oauth2/authorize?response_type=code&client_id=23TLHX&redirect_uri=http://127....

App configuration:
- OAuth 2.0 Application Type: Personal
- Redirect URL: http://127.0.0.1:5001/fitbit-callback
- Default Access Type: Read & Write

What I've tried:
- Created two different apps (both return 403)
- Tested in different browsers and incognito mode
- Verified all settings match Fitbit documentation
- The 403 appears even when pasting the authorize URL directly into the browser

Can you please check if my account has any restrictions preventing Personal app OAuth authorization? The error occurs before I even see the login/consent screen. Fitbit staff can identify my account from my forum profile.

Thank you!

Best Answer
0 Votes
1 REPLY 1

Hi @Chinnam , and welcome to the forums!

It might be the redirect url you're using is causing the issue. 
In the documentation on Redirect URLsFitbit only supports https for redirect URLs.
As also noted in https://dev.fitbit.com/build/reference/web-api/developer-guide/getting-started/#Registering-an-Appli... all URLs must use https.

If you have further questions or still encounter issues after changing your redirect URL, please let us know!

I'll also place the link to the HTTP status codes from the Fitbit Web APIs (including error codes) here for future reference: https://dev.fitbit.com/build/reference/web-api/troubleshooting-guide/error-messages/

Best Answer
0 Votes