ErrorCS2 API errors

Steam API 403 Forbidden: the fix.

A 403 from api.steampowered.com means access is denied and retrying will not help. The usual causes: a missing or invalid key, or a publisher-only method called with a regular user key. Check the key= parameter first; Valve's own description of 403 says exactly that.

  • Access denied
  • Do not retry
  • Check key= first
GET /cs2/matches/results?limit=2200 OK
$ curl "https://api.citoapi.com/api/v1/cs2/matches/results?limit=2" \ -H "x-api-key: $CITO_API_KEY"
{  "success": true,  "data": [    {      "id": "cs2-match-2398974",      "eventName": "ROG JOURNEY Autumn 2026",      "bestOf": 3,      "team1Name": "Ninjas in Pyjamas",      "team2Name": "Eternal Fire",      "score": { "team1": 2, "team2": 0 }    },    {      "id": "cs2-match-2398896",      "eventName": "FOX Legacy Season 1",      "bestOf": 3,      "team1Name": "SAW",      "team2Name": "Lazer Cats",      "score": { "team1": 2, "team2": 0 }    }    ...  ]}

The error

What you see
HTTP/1.1 403 Forbidden
<html><head><title>Forbidden</title></head><body><h1>Forbidden</h1>
Access is denied. Retrying will not help. Please verify your <pre>key=</pre> parameter.</body></html>

What does Steam's 403 Forbidden mean?

Valve documents 401 and 403 the same way: access is denied, retrying will not help, verify the key= parameter. The body is an HTML page, not JSON, which is why JSON parsers often fail on it first.

Why does it happen?

Probing the API on 2026-10-03, CS2 methods such as ICSGOPlayers_730/GetNextMatchSharingCode returned 403 both with no key and with a made-up key. Some other interfaces answer a missing key with 401 instead.

  • No key= parameter, or a key with a typo, quotes or whitespace.
  • A regular Steam user key used on a method that needs a publisher key (partner.steam-api.com methods).
  • A key that was revoked, for example after the account lost access or Valve flagged it.
  • Repeated 403-producing traffic, which Valve answers with stricter per-IP rate limits.

A private Steam profile is not the usual cause: methods such as GetOwnedGames return only what is visible to the caller rather than a 403.

How do I fix it?

Make one known-good call with your key to confirm it works, then compare it with the failing request. If the known-good call also returns 403, the key is the problem; register or regenerate it at steamcommunity.com/dev/apikey.

Python: check the key, then the failing call
import requests

KEY = "YOUR_STEAM_WEB_API_KEY".strip()

# 1. Known-good method: a valid key returns JSON here.
r = requests.get("https://api.steampowered.com/ISteamWebAPIUtil/GetSupportedAPIList/v1/",
                 params={"key": KEY}, timeout=10)
print("key check:", r.status_code)

# 2. The failing call. Inspect the raw body: Steam's 403 is HTML, not JSON.
r = requests.get("https://api.steampowered.com/ICSGOPlayers_730/GetNextMatchSharingCode/v1/",
                 params={"key": KEY, "steamid": "7656119...", "steamidkey": "AAAA-AAAAA-AAAA",
                         "knowncode": "CSGO-xxxxx-xxxxx-xxxxx-xxxxx-xxxxx"}, timeout=10)
print(r.status_code, r.headers.get("content-type"), r.text[:200])

How does the CS2 API make Steam 403s impossible?

For professional CS2 data there is no Steam key to get wrong: the CS2 API needs one key of its own and returns structured JSON errors with a code and a docs link instead of an HTML page. Steam remains the only source for a player's own matchmaking games.

Frequently asked questions

Something missing? Email support@citoapi.com.

Why does the Steam API return 403 with a valid key?

Usually the method needs a publisher key, or the key sent is not the one you think (whitespace, quotes, an old value). Test the key on GetSupportedAPIList first.

Should I retry a Steam 403?

No. Valve states retrying will not help, and repeated 403s lead to stricter per-IP rate limits.

Does a private profile cause a 403?

Not usually. Methods such as GetOwnedGames return only data visible to the caller, so a private profile tends to produce empty results rather than a 403.

See pricing

Build CS2 live score apps

Free is for building and testing. Paid plans add commercial use, real-time live data and the full archive.