Not in allowlist
type | https://docs.frem.sh/reference/api/errors/not-in-allowlist |
| HTTP status | 403 Forbidden |
What it means
The credential is valid, but an allowlist refuses this request. Two allowlists return this error:
- The org’s IP allowlist: your IP address is not on it, or the org does not allow this credential from fremforge-hosted runners.
- An environment’s list of allowed deployment approvers: you are not on it.
Example detail messages returned with this error:
- The acme organisation restricts access to an IP allowlist, and your IP address (198.51.100.7) is not on it. Connect from an approved network, or ask an owner to review the allowlist under Security -> IP allowlist.
- The acme organisation does not allow this credential from fremforge-hosted runners. Use the job’s own token, or ask an owner to allow fremforge-hosted runners under Security -> IP allowlist.
- You are not on the allowed-approvers list for this environment.
What to do
For the IP allowlist, connect from a network on the list, or ask an org owner to add your range. An owner who is locked out can turn on break-glass. In a CI job on fremforge-hosted runners, use the job’s own token. For deployment approvals, ask an org owner to add you to the environment’s approvers.
Response shape
All fremforge API errors are RFC 9457 problem+json:
{
"type": "https://docs.frem.sh/reference/api/errors/not-in-allowlist",
"title": "Forbidden",
"status": 403,
"detail": "..."
}Branch on type, not on title or detail - those are human-readable and may be reworded.