How to Fix Midjourney API Error 401 & 403 Forbidden
Updated 9/24/2026
When programmatically triggering Midjourney generations, encountering an HTTP 401 (Unauthorized) or HTTP 403 (Forbidden) error means your authentication handshake has failed or your account lacks the necessary permissions to execute commands in the targeted channel.
Because Midjourney does not provide an official public REST API, developers run into these authorization issues when utilizing Discord bot integrations, user token automations, or third-party wrappers. Use this guide to resolve authentication blocks step-by-step.
Understanding 401 and 403 authentication failures
- Error 401 (Unauthorized): The server cannot verify your identity. Your Discord token, session cookie, or API key is missing, malformed, or has expired.
- Error 403 (Forbidden): The server knows who you are, but your account or bot does not have permission to perform the requested action (such as invoking /imagine in a specific Discord server or channel).
Step 1: Verify your Discord User Token or API Key
If your integration relies on a Discord User Token (often used in automation scripts, though against Discord's ToS) or a Bot Token, a 401 error indicates this token is no longer valid.
1. Check for token expiration: Discord user tokens expire periodically, especially if you change your Discord password or enable/disable Two-Factor Authentication (2FA). Regenerate your token if necessary. 2. Verify environment variables: Ensure your code is pulling the token correctly. Hardcoded tokens can be truncated or corrupted during Git commits. Use a .env file and verify your initialization code: `javascript const token = process.env.DISCORD_TOKEN; if (!token) throw new Error("Missing Discord authorization token."); ` 3. Do not share sessions: Logging into your Discord account from multiple geographical locations simultaneously while running an automation script can trigger a security flag, immediately invalidating your token and returning a 401.
Step 2: Check bot scopes and channel permissions
If your credentials are correct but you receive a 403 Forbidden error, your automation is attempting to execute commands in a space where it is restricted.
- Verify Channel Access: Ensure the channel ID specified in your API call actually exists and that your account/bot is a member of that channel.
- Check Permissions: In Discord, right-click the target channel, select Edit Channel, and go to Permissions. Ensure the role assigned to your token has the following permissions enabled:
- *View Channel*
- *Send Messages*
- *Use Slash Commands* (crucial for triggering Midjourney's /imagine and /upscale inputs)
- *Read Message History*
- Test manually: Log into the Discord interface using the same account credentials. Try to type /imagine in that specific channel. If you cannot do it manually, your script will return a 403.
Step 3: Accept Midjourney's Terms of Service (ToS)
Newly created accounts or accounts with reset terms will block all programmatic requests with a 403 error until the terms are accepted.
- Log into the Discord client with the account tied to your integration.
- Send a simple /imagine prompt: test command in a direct message to the Midjourney bot or a public server.
- If a pop-up window or bot response appears asking you to accept the updated Terms of Service, click Accept ToS.
- Restart your application script and test the integration again.
Step 4: Resolve Captcha or Verification Locks
Discord frequently flags automated programmatic access (self-bots) and blocks requests with a 403 Forbidden error until a security verification is completed.
- Check your email or Discord notifications to see if your account has been locked or flagged for verification.
- If Discord has flagged your account, you must log in through a web browser or official app and complete the captcha challenge manually.
- To prevent future verification locks, slow down your request rate and avoid sending repetitive, identical payloads in short intervals.
When to escalate
- Account Suspension: If you receive a persistent 401 or 403 across all channels and cannot log in via the official Discord client, check your email. Your account may have been suspended by Discord for violating their terms of service regarding automated self-bots.
- Third-Party API Downtime: If you are paying for an unofficial Midjourney API service, a 403 error often indicates their upstream accounts have been banned. Contact your provider’s support desk to verify their service status.