Tickd.ai
API errors

Gemini API 403 Forbidden Error: How to Fix

Updated 10/4/2026

A 403 Forbidden or Permission Denied error from the Gemini API indicates that while your API key was successfully read and recognized by Google's servers, the key does not have authorization to access the specific resource, model, or feature you requested. This is fundamentally different from a 401 Unauthorized error, which indicates an invalid or malformed API key.

This guide outlines the most common causes of the Gemini API 403 error and provides clear, step-by-step instructions to resolve them.

1. Enable the Generative Language API in Google Cloud If you created your API key using the Google Cloud Console instead of Google AI Studio, your Cloud project must explicitly have the **Generative Language API** enabled. If it is disabled, your requests will return a 403 error.

  1. Open the [Google Cloud Console](https://console.cloud.google.com/).
  2. Select the specific project associated with your API key from the top project dropdown.
  3. Navigate to APIs & Services > Library via the left-hand sidebar.
  4. In the search bar, type Generative Language API and press Enter.
  5. Click on the Generative Language API result.
  6. If the button says Enable, click it. If it says Manage, the API is already active.

2. Check API Key Restrictions Google Cloud allows developers to apply security restrictions to API keys to prevent unauthorized usage. If your key has API or application restrictions, it may block your Gemini API requests.

  1. Go to APIs & Services > Credentials in your Google Cloud Console.
  2. Click on the name of the API key you are using to edit its settings.
  3. Scroll down to API restrictions.
  4. If "Restrict key" is selected, ensure that Generative Language API is checked in the dropdown list of allowed APIs. If it is missing, your code will receive a 403 error.
  5. Scroll to Application restrictions. If you have restricted the key by IP addresses or HTTP referrers, verify that your development server's external IP address or website domain matches those rules exactly.
  6. Save any changes and wait up to 5 minutes for Google's servers to update global permissions.

3. Verify Regional and IP Availability The Gemini API is not available in all countries. If your application is deployed on a virtual private server (VPS), cloud hosting provider (such as Vercel, AWS, or Heroku), or behind a VPN, the host server's physical IP address must be located in a supported region.

1. Review Google’s official list of [Gemini API available regions](https://ai.google.dev/gemini-api/docs/available-regions). 2. Run a command on your application server to determine its outbound IP geographic location: `bash curl ipinfo.io ` 3. If your server is hosted in an unsupported country, you must redeploy your application or backend function to an allowed region (such as us-central1 or europe-west9 for Google Cloud users).

4. Resolve Billing and Plan Limits Free-tier accounts in Google AI Studio have strict usage limits. If your project exceeds these limits or if you are using specific models that require a paid plan, Google will block requests with a 403 error.

  1. Visit [Google AI Studio](https://aistudio.google.com/).
  2. Navigate to your plan or billing settings.
  3. Verify whether your account has been downgraded or suspended due to outstanding payments.
  4. If you are using enterprise-grade or tuned models, link a valid Google Cloud Billing account to your project to move to the pay-as-you-go tier.

5. Correct Service Account IAM Permissions If you are authenticating your application using a Service Account JSON key instead of a standard API key, the service account must have the correct Identity and Access Management (IAM) role.

  1. Go to IAM & Admin > IAM in your Google Cloud Console.
  2. Locate your service account email address in the user list.
  3. Ensure the service account has been assigned at least the GenAI Developer or Vertex AI User role.
  4. If the service account only has basic reader permissions, click the pencil icon next to the account name and add the appropriate generative AI roles.

When to Escalate If you have verified that your billing is active, the Generative Language API is enabled, the API key has no restrictions, and you are operating from a supported country, your Google Workspace organization policy may be blocking AI services.

If you are using a corporate Google Workspace account, contact your organization's IT or Workspace administrator to ensure that Early Access Apps or Generative AI Features are explicitly enabled for your organizational unit.

While you're here

Tickd is more than troubleshooting — these three are free and take seconds.

Agent BuilderDesign your own AI agent and export it to ChatGPT, Claude, Gemini or Grok.Build one free