Steam API 403 Forbidden: the fix.
A 403 from api.steampowered.com means access is denied and retrying will not help. The usual causes: a missing or invalid key, or a publisher-only method called with a regular user key. Check the key= parameter first; Valve's own description of 403 says exactly that.
- Access denied
- Do not retry
- Check key= first
{ "success": true, "data": [ { "id": "cs2-match-2398974", "eventName": "ROG JOURNEY Autumn 2026", "bestOf": 3, "team1Name": "Ninjas in Pyjamas", "team2Name": "Eternal Fire", "score": { "team1": 2, "team2": 0 } }, { "id": "cs2-match-2398896", "eventName": "FOX Legacy Season 1", "bestOf": 3, "team1Name": "SAW", "team2Name": "Lazer Cats", "score": { "team1": 2, "team2": 0 } } ... ]}The error
HTTP/1.1 403 Forbidden
<html><head><title>Forbidden</title></head><body><h1>Forbidden</h1>
Access is denied. Retrying will not help. Please verify your <pre>key=</pre> parameter.</body></html>What does Steam's 403 Forbidden mean?
Valve documents 401 and 403 the same way: access is denied, retrying will not help, verify the key= parameter. The body is an HTML page, not JSON, which is why JSON parsers often fail on it first.
Why does it happen?
Probing the API on 2026-10-03, CS2 methods such as ICSGOPlayers_730/GetNextMatchSharingCode returned 403 both with no key and with a made-up key. Some other interfaces answer a missing key with 401 instead.
- No key= parameter, or a key with a typo, quotes or whitespace.
- A regular Steam user key used on a method that needs a publisher key (partner.steam-api.com methods).
- A key that was revoked, for example after the account lost access or Valve flagged it.
- Repeated 403-producing traffic, which Valve answers with stricter per-IP rate limits.
A private Steam profile is not the usual cause: methods such as GetOwnedGames return only what is visible to the caller rather than a 403.
How do I fix it?
Make one known-good call with your key to confirm it works, then compare it with the failing request. If the known-good call also returns 403, the key is the problem; register or regenerate it at steamcommunity.com/dev/apikey.
import requests
KEY = "YOUR_STEAM_WEB_API_KEY".strip()
# 1. Known-good method: a valid key returns JSON here.
r = requests.get("https://api.steampowered.com/ISteamWebAPIUtil/GetSupportedAPIList/v1/",
params={"key": KEY}, timeout=10)
print("key check:", r.status_code)
# 2. The failing call. Inspect the raw body: Steam's 403 is HTML, not JSON.
r = requests.get("https://api.steampowered.com/ICSGOPlayers_730/GetNextMatchSharingCode/v1/",
params={"key": KEY, "steamid": "7656119...", "steamidkey": "AAAA-AAAAA-AAAA",
"knowncode": "CSGO-xxxxx-xxxxx-xxxxx-xxxxx-xxxxx"}, timeout=10)
print(r.status_code, r.headers.get("content-type"), r.text[:200])How does the CS2 API make Steam 403s impossible?
For professional CS2 data there is no Steam key to get wrong: the CS2 API needs one key of its own and returns structured JSON errors with a code and a docs link instead of an HTML page. Steam remains the only source for a player's own matchmaking games.
Frequently asked questions
Something missing? Email support@citoapi.com.
Why does the Steam API return 403 with a valid key?
Usually the method needs a publisher key, or the key sent is not the one you think (whitespace, quotes, an old value). Test the key on GetSupportedAPIList first.
Should I retry a Steam 403?
No. Valve states retrying will not help, and repeated 403s lead to stricter per-IP rate limits.
Does a private profile cause a 403?
Not usually. Methods such as GetOwnedGames return only data visible to the caller, so a private profile tends to produce empty results rather than a 403.
Related
- Steam Web API for CS2 tutorialStep by step through Steam's CS2 methods, and where they stop.
- CS2 match results APIFinal series scores, map scores and box scores.
- Steam API 429 Too Many RequestsThrottled by Steam: backoff that works and how to stop triggering it.
- CS2 match history not foundThere is no Steam match history endpoint for CS2. What to call instead.
- Steam CS2 APIWhat Valve's Steam Web API covers for CS2, and the match-data gap.
- How to get CS2 match dataResults, maps and player lines for any pro match in three requests.
Build CS2 live score apps
Free is for building and testing. Paid plans add commercial use, real-time live data and the full archive.