<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 403 on valid access token using the authorization code flow in Spotify for Developers</title>
    <link>https://community.spotify.com/t5/Spotify-for-Developers/403-on-valid-access-token-using-the-authorization-code-flow/m-p/6180587#M14401</link>
    <description>&lt;P&gt;Have you setup your redirect URIs correctly for your production machine (not just localhost)?&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jul 2024 08:23:43 GMT</pubDate>
    <dc:creator>LambertSpot</dc:creator>
    <dc:date>2024-07-08T08:23:43Z</dc:date>
    <item>
      <title>403 on valid access token using the authorization code flow</title>
      <link>https://community.spotify.com/t5/Spotify-for-Developers/403-on-valid-access-token-using-the-authorization-code-flow/m-p/6179665#M14378</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm having a bit of an issue with the Spotify Web API. I suspect the IP address of my production machine may have been put on some sort of ban list. I won't be giving out the IP address on the forum, but if it helps, I am using a machine from Hetzner.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Authenticating via the authorization code flow works just fine on my local machine during testing, but as soon as my application runs on my production machine, authenticating does not work at all. Please note that my Spotify application is in development mode, and has not been approved for a quota extension just yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: Forgot to add this, but when I use an access token that was provided to my local machine, and when I try to use that same token on the production machine, it throws a 403 error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Marino&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jul 2024 18:20:22 GMT</pubDate>
      <guid>https://community.spotify.com/t5/Spotify-for-Developers/403-on-valid-access-token-using-the-authorization-code-flow/m-p/6179665#M14378</guid>
      <dc:creator>marinofranz</dc:creator>
      <dc:date>2024-07-07T18:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: 403 on valid access token using the authorization code flow</title>
      <link>https://community.spotify.com/t5/Spotify-for-Developers/403-on-valid-access-token-using-the-authorization-code-flow/m-p/6180006#M14394</link>
      <description>&lt;P&gt;It may not be that your prod. server is banned but your prod server itself must request an accessToken to make requests. You said that the local machine and prod server use the same token; I don't think it's part of the official OAuth standard, but Spotify might extend security of access tokens by associating them with an IP or something. Otherwise a malicious dev could request one access token, distribute it to a bunch of remote servers and attempt a DDoS on Spotify using that one access token. Otherwise, if you're getting 403, it's also possible the access token scopes don't cover the end point you're hitting, but if it works in your local environment that's less likely to be the case&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jul 2024 22:12:41 GMT</pubDate>
      <guid>https://community.spotify.com/t5/Spotify-for-Developers/403-on-valid-access-token-using-the-authorization-code-flow/m-p/6180006#M14394</guid>
      <dc:creator>smacklol</dc:creator>
      <dc:date>2024-07-07T22:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: 403 on valid access token using the authorization code flow</title>
      <link>https://community.spotify.com/t5/Spotify-for-Developers/403-on-valid-access-token-using-the-authorization-code-flow/m-p/6180012#M14395</link>
      <description>&lt;P&gt;I understand that they may use that as a precaution, but I have also tried obtaining an access token by starting the authentication flow on the production server, however, it returns a 403 after requesting a refresh token. I've made sure that my scopes are correct. Not only that, but I should not need a scope to request a new refresh / access token.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jul 2024 22:18:57 GMT</pubDate>
      <guid>https://community.spotify.com/t5/Spotify-for-Developers/403-on-valid-access-token-using-the-authorization-code-flow/m-p/6180012#M14395</guid>
      <dc:creator>marinofranz</dc:creator>
      <dc:date>2024-07-07T22:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: 403 on valid access token using the authorization code flow</title>
      <link>https://community.spotify.com/t5/Spotify-for-Developers/403-on-valid-access-token-using-the-authorization-code-flow/m-p/6180587#M14401</link>
      <description>&lt;P&gt;Have you setup your redirect URIs correctly for your production machine (not just localhost)?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 08:23:43 GMT</pubDate>
      <guid>https://community.spotify.com/t5/Spotify-for-Developers/403-on-valid-access-token-using-the-authorization-code-flow/m-p/6180587#M14401</guid>
      <dc:creator>LambertSpot</dc:creator>
      <dc:date>2024-07-08T08:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: 403 on valid access token using the authorization code flow</title>
      <link>https://community.spotify.com/t5/Spotify-for-Developers/403-on-valid-access-token-using-the-authorization-code-flow/m-p/6181140#M14403</link>
      <description>&lt;P&gt;Yes, I have set up the redirects correctly. There should not be anything to change in the routes directly when switching from development to production.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 15:55:42 GMT</pubDate>
      <guid>https://community.spotify.com/t5/Spotify-for-Developers/403-on-valid-access-token-using-the-authorization-code-flow/m-p/6181140#M14403</guid>
      <dc:creator>marinofranz</dc:creator>
      <dc:date>2024-07-08T15:55:42Z</dc:date>
    </item>
  </channel>
</rss>

