# Adobe OAuth succeeds, but all \[Frame.io\](http://frame.io/) API endpoints return 403

**URL:** <https://forum.frame.io/t/adobe-oauth-succeeds-but-all-frame-io-http-frame-io-api-endpoints-return-403/3243>\
**Category:** Help\
**Created:** [March 19, 2026, 9:49pm UTC](https://forum.frame.io/t/adobe-oauth-succeeds-but-all-frame-io-http-frame-io-api-endpoints-return-403/3243 "2026-03-19T21:49:06Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![newvisions](https://avatars.discourse-cdn.com/v4/letter/n/57b2e6/32.png) [@newvisions](https://forum.frame.io/u/newvisions)\
**Post date:** [March 19, 2026, 9:49pm UTC](https://forum.frame.io/t/adobe-oauth-succeeds-but-all-frame-io-http-frame-io-api-endpoints-return-403/3243/1 "2026-03-19T21:49:06Z")

</div>

Hi team —

I’m trying to set up a fresh [Frame.io](http://frame.io/) API integration using Adobe IMS OAuth and I’m consistently getting blocked at the API layer even though the OAuth flow itself is working.

**What’s working**

- Created a fresh Adobe Developer Console project

- Added the [Frame.io](http://frame.io/) API

- Configured OAuth Web App credentials

- Used Authorization Code flow (not server-to-server)

- Requested scopes:

• openid

• additional\_info.roles

• offline\_access

• profile

• email

- User successfully approves the app

- Token exchange succeeds

- Access + refresh tokens are issued successfully

**What’s failing**

All [Frame.io](http://frame.io/) API calls return **403 Forbidden** , including:

- GET /v2/me

- GET /v4/me

- GET /v4/accounts

- GET /v4/teams

- GET /v2/teams

- GET /v4/assets

So this does **not** appear to be just a /me endpoint issue.

**Additional notes**

- This was tested with a brand new Adobe app/client

- Old local tokens/config were deleted before retrying

- The access token decodes correctly and includes:

• openid, additional\_info.roles, offline\_access, profile, email, AdobeID

- OAuth flow and token issuance are both successful

- The same token fails across both v2 and v4 API endpoints

**Question**

Does this indicate that my [Frame.io](http://frame.io/) user/workspace is not fully linked or entitled for API access on the backend, even if Adobe login appears to be working in the UI?

If so, what exact account/workspace state should I verify, or what needs to be enabled on your side?

Thanks — trying to determine whether this is still a configuration issue on my end, or whether the account linkage / API entitlement needs support intervention.

---

<div class="post-metadata">

**Author:** ![rosiec](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.frame.io/rosiec/32/518_2.png) [@rosiec](https://forum.frame.io/u/rosiec)\
**Post date:** [March 19, 2026, 10:26pm UTC](https://forum.frame.io/t/adobe-oauth-succeeds-but-all-frame-io-http-frame-io-api-endpoints-return-403/3243/2 "2026-03-19T22:26:38Z")

</div>

Hi @newvisions,

Sorry to hear you’re running into some trouble. Based on your description, it doesn’t sound like an issue with the token, especially if it is decoding correctly.

It sounds like you’ve already done this, but something that is always good to check is that you have successfully linked your Adobe and Frame.io accounts. Instructions on how to do so can be found here: [Connecting to Adobe authentication | Frame.io V4 Knowledge Center](https://help.frame.io/en/articles/11758018-connecting-to-adobe-authentication)

If that is showing up as successfully linked, the next thing I’d check is the headers. Feel free to send over an example of the requests you’re sending (header included), along with the full response body and I’ll be happy to take a look to troubleshoot further!

---

<div class="post-metadata">

**Author:** ![newvisions](https://avatars.discourse-cdn.com/v4/letter/n/57b2e6/32.png) [@newvisions](https://forum.frame.io/u/newvisions)\
**Post date:** [March 19, 2026, 11:00pm UTC](https://forum.frame.io/t/adobe-oauth-succeeds-but-all-frame-io-http-frame-io-api-endpoints-return-403/3243/3 "2026-03-19T23:00:25Z")

</div>

Thanks — yes, Adobe and Frame.ioappear to be linked successfully in the UI.

Here are the requests I’m sending:

GET [https://api.frame.io/v4/me](https://api.frame.io/v4/me)

Header: Authorization: Bearer \<access\_token\>

GET [https://api.frame.io/v4/accounts](https://api.frame.io/v4/accounts)

Header: Authorization: Bearer \<access\_token\>

Both return:

Status: 403 Forbidden

Response body:

403 Forbidden
# 403 Forbidden

Additional context:

- Fresh Adobe Developer Console project

- Frame.ioAPI added

- OAuth Web App configured

- Authorization Code flow succeeds

- Token exchange succeeds

- Access token decodes correctly

- Token scopes include: openid, additional\_info.roles, offline\_access, profile, email, AdobeID

At this point, does this pattern suggest a backend entitlement/workspace access issue rather than an OAuth/token issue?

---

<div class="post-metadata">

**Author:** ![CharlieAnderson](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.frame.io/charlieanderson/32/491_2.png) [@CharlieAnderson](https://forum.frame.io/u/CharlieAnderson)\
**Post date:** [March 19, 2026, 11:33pm UTC](https://forum.frame.io/t/adobe-oauth-succeeds-but-all-frame-io-http-frame-io-api-endpoints-return-403/3243/4 "2026-03-19T23:33:18Z")

</div>

hi @newvisions 403 means “unauthorized” or “forbidden” meaning you dont have access. Can you go here, click login, and then hit `Send Request`? [https://next.developer.frame.io/platform/api-reference/accounts/index?explorer=true](https://next.developer.frame.io/platform/api-reference/accounts/index?explorer=true)

Let us know what you learn as this will tell us whether it’s an account issue or some other issue.

---

<div class="post-metadata">

**Author:** ![newvisions](https://avatars.discourse-cdn.com/v4/letter/n/57b2e6/32.png) [@newvisions](https://forum.frame.io/u/newvisions)\
**Post date:** [March 20, 2026, 1:43am UTC](https://forum.frame.io/t/adobe-oauth-succeeds-but-all-frame-io-http-frame-io-api-endpoints-return-403/3243/5 "2026-03-20T01:43:33Z")

</div>

Thanks — I dug further and found an important clue.

I tested the built-in API explorer.

I was able to log in successfully and GET /v4/accounts returned 200 with account data, including my account.

I also looked at the explorer’s generated request/code sample and confirmed that the token being used there belongs to a different client\_id than my custom Adobe app.

So it appears the built-in explorer is authenticating through a first-party Frame client, while tokens issued to my own custom Adobe app still fail.

For my custom app:

- Adobe OAuth Authorization Code flow succeeds

- token exchange succeeds

- token decodes correctly

- scopes include:

openid, additional\_info.roles, offline\_access, profile, email, AdobeID

But requests like:

/v4/me

v4/accounts

still fail when using the token from my custom app.

Also, if OAuth app type matters here:

- should this be configured as **OAuth Web App**

- **Native App**

- or some other app type for Frame V4?

At this point the account itself appears to have API access (since the explorer works), but my custom client does not.

---

<div class="post-metadata">

**Author:** ![CharlieAnderson](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.frame.io/charlieanderson/32/491_2.png) [@CharlieAnderson](https://forum.frame.io/u/CharlieAnderson)\
**Post date:** [March 20, 2026, 4:58pm UTC](https://forum.frame.io/t/adobe-oauth-succeeds-but-all-frame-io-http-frame-io-api-endpoints-return-403/3243/6 "2026-03-20T16:58:10Z")

</div>

@newvisions the built in explorer uses the Adobe Developer Console project that we set up, we did it this way to ensure that people could test their integrations as well as help us troubleshoot issues as they come up (as in your case). It’s no different than how anyone else can set up their own credentials.

The fact that you can get a 200 request on the explorer means there’s some issue in how you’re authenticating or how you’re exchanging the auth token for an access token (since we’ve ruled out general API access).

Can you share the exact code or curl command you’re using to call the API? Specifically:

- How you’re doing the token exchange (the full request to the token endpoint, redact the secret)
- How you’re attaching the token to your API calls

You can DM me if you’d like if it’s sensitive info.

Also can you confirm these steps are taken correctly?

1. **Confirm the [Frame.io](http://Frame.io) API specifically** is added to your Adobe Developer Console project.

2. **Credential check** — Make sure you’re using the client\_id and client\_secret from your OAuth Web App credential specifically.

3. **Authorization URL** — Confirm you’re passing the correct client\_id, redirect\_uri, and response\_type=code to the Adobe IMS authorize endpoint.

4. **Redirect URI match** — The redirect\_uri in your auth request must exactly match what’s registered in the Developer Console, including trailing slashes.

5. **Auth code capture** — After approval, confirm you’re extracting the `code` parameter from the redirect correctly.

6. **Token exchange** — This is the most common failure point. Confirm you’re POSTing to the Adobe IMS token endpoint with: grant\_type=authorization\_code, the auth code, client\_id, client\_secret, and the same redirect\_uri used in step 3.

7. **Correct token** — The token response returns both an access\_token and an id\_token. Make sure you’re using the **access\_token** , not the id\_token.

8. **Header format** — Confirm your Authorization header is exactly `Authorization: Bearer <token>` — capital B, single space, no extra whitespace or quotes around the token value.

9. **Token freshness** — Auth codes expire within minutes. If there’s any delay between getting the code and exchanging it, you may end up with a bad token.

10. **API base URL** — Confirm you’re hitting `https://api.frame.io/v4/` exactly, not /v2

If you can share the code or curl commands for steps 3, 6, and your actual API call (redact the secret), that’ll help us spot where it’s breaking down.

---

<div class="post-metadata">

**Author:** ![newvisions](https://avatars.discourse-cdn.com/v4/letter/n/57b2e6/32.png) [@newvisions](https://forum.frame.io/u/newvisions)\
**Post date:** [March 20, 2026, 6:44pm UTC](https://forum.frame.io/t/adobe-oauth-succeeds-but-all-frame-io-http-frame-io-api-endpoints-return-403/3243/7 "2026-03-20T18:44:08Z")

</div>

Hi Charlie, how do I dm you? Not seeing an option on your profile

---

<div class="post-metadata">

**Author:** ![CharlieAnderson](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.frame.io/charlieanderson/32/491_2.png) [@CharlieAnderson](https://forum.frame.io/u/CharlieAnderson)\
**Post date:** [March 21, 2026, 3:10pm UTC](https://forum.frame.io/t/adobe-oauth-succeeds-but-all-frame-io-http-frame-io-api-endpoints-return-403/3243/8 "2026-03-21T15:10:26Z")

</div>

hi @newvisions it’s a timed thing (since you are a new user) just takes a few days to validate or a few posts. Should unlock soon-ish. Was implemented a while back since we had users getting spammed by bots

---

<div class="post-metadata">

**Author:** ![newvisions](https://avatars.discourse-cdn.com/v4/letter/n/57b2e6/32.png) [@newvisions](https://forum.frame.io/u/newvisions)\
**Post date:** [March 23, 2026, 2:09am UTC](https://forum.frame.io/t/adobe-oauth-succeeds-but-all-frame-io-http-frame-io-api-endpoints-return-403/3243/9 "2026-03-23T02:09:02Z")

</div>

Gotcha, Ill keep an eye on that and flag you when I can dm you

Best,

Dylan Brannigan  
New Visions Productions  
(718) 612-6274  
[www.ournewvisions.com](http://www.ournewvisions.com)

---

<div class="post-metadata">

**Author:** ![CharlieAnderson](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.frame.io/charlieanderson/32/491_2.png) [@CharlieAnderson](https://forum.frame.io/u/CharlieAnderson)\
**Post date:** [March 24, 2026, 9:50pm UTC](https://forum.frame.io/t/adobe-oauth-succeeds-but-all-frame-io-http-frame-io-api-endpoints-return-403/3243/10 "2026-03-24T21:50:07Z")

</div>

@newvisions we just released our Auth SDK for python, can you try this to see if it fixes your issues?

> [@Introducing OAuth 2.0 Authentication in the Frame.io Python SDK](https://forum.frame.io/t/introducing-oauth-2-0-authentication-in-the-frame-io-python-sdk/3252):
>
> #Feedback Introducing OAuth 2.0 Authentication in the [Frame.io](http://Frame.io) Python SDK We’re excited to announce that the [Frame.io](http://Frame.io) Python SDK (frameio) now includes built-in OAuth 2.0 authentication. No more managing tokens manually or dealing with 401 errors anymore— the SDK handles the full lifecycle for you. What’s New The new frameio.auth module supports three OAuth 2.0 flows: FlowBest For Server-to-ServerBackend services, scripts, automation — no user interaction needed Web AppServer-side apps (Flask…

---

<div class="post-metadata">

**Author:** ![newvisions](https://avatars.discourse-cdn.com/v4/letter/n/57b2e6/32.png) [@newvisions](https://forum.frame.io/u/newvisions)\
**Post date:** [March 25, 2026, 12:28pm UTC](https://forum.frame.io/t/adobe-oauth-succeeds-but-all-frame-io-http-frame-io-api-endpoints-return-403/3243/11 "2026-03-25T12:28:12Z")

</div>

Cool! Will try this later today or Friday when I have more ops time scheduled and report back

---

<div class="post-metadata">

**Author:** ![newvisions](https://avatars.discourse-cdn.com/v4/letter/n/57b2e6/32.png) [@newvisions](https://forum.frame.io/u/newvisions)\
**Post date:** [April 7, 2026, 8:37pm UTC](https://forum.frame.io/t/adobe-oauth-succeeds-but-all-frame-io-http-frame-io-api-endpoints-return-403/3243/12 "2026-04-07T20:37:08Z")

</div>

Thanks for the help! Had to remove email from my auth scope and that fixed it!
