# Can't solve 403 forbidden

**URL:** https://discourse.sst.dev/t/cant-solve-403-forbidden/1707
**Category:** General
**Created:** [March 30, 2020, 10:47pm UTC](https://discourse.sst.dev/t/cant-solve-403-forbidden/1707 "2020-03-30T22:47:24Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![bc2012](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/bc2012/32/804_2.png) [@bc2012](https://discourse.sst.dev/u/bc2012)
#### Post date: [March 30, 2020, 10:47pm UTC](https://discourse.sst.dev/t/cant-solve-403-forbidden/1707/1 "2020-03-30T22:47:24Z")

</div>

I have completed the Notes App tutorial (the only change being that I am connecting to a MongoDB).  
The Notes App was created by using the infrastructure ymls in Resources.  
Everything is working.

I then decided to alter the serverless.yml and add back in the supplied ‘hello’ api (including adding the handler.js to the project).  
With that done I then executed $serverless deploy —stage dev

When I run an ‘npx aws-api-gateway-cli-test’ with the ‘—path-template=‘/hello’’ it gives me a ’403 forbidden’.  
Executing in the Amazon API Gateway gives 200.

**Aside** : the reason I added the supplied ‘hello’ API back in is because I have also set up a new project that is having the same issue - I can’t call any of it’s APIs as they all give ’403 forbidden’.

I’ve tried all the troubleshooting I could find on the web but no joy.

Here is the hello API as defined in the serverless.yml:

> functions:  
> hello:  
> handler: handler.hello  
> events:  
> - http:  
> path: hello  
> method: get  
> authorizer: aws\_iam

The only other difference from the tutorial is that as I am not connecting to Dynamo I don’t have any iamRoleStatements defined in the serverless.yml.

Any help greatly appreciated as I completely new to this.

---

<div class="post-metadata">

### Author: ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)
#### Post date: [April 13, 2020, 8:18pm UTC](https://discourse.sst.dev/t/cant-solve-403-forbidden/1707/2 "2020-04-13T20:18:30Z")

</div>

Sometimes the 403 could be that the URL is invalid. We added a new section on debugging issues, that might help:

> **[Debugging Full-Stack Serverless Apps](https://serverless-stack.com/chapters/debugging-full-stack-serverless-apps.html)**
>
> In this chapter we look at the debugging setup and workflow for full-stack Serverless apps. We’ll cover some of the most common errors, including errors inside and outside Lambda functions, timeouts and out-of-memory errors.
