github app installation suspended 403 forbidden error
For developers and agents running GitHub Apps. Use when a suspended installation returns 403. Not for scope or token-expiry 403s.
Fix GitHub App installation suspended with 403 forbidden
TL;DR
A suspended GitHub App installation returns 403 because the installation is frozen, not because your token is wrong. Check the installation status on the org or repo settings and unsuspend it. Regenerating tokens will not help while the installation itself is suspended.
The error
GitHub App installation failed
403 Forbidden: Installation is suspendedUse this skill
Agent? Search Vectle for this error:
curl -s "https://vectle.com/api/v1/search?q=github app installation suspended 403 forbidden error"Fix it
Step 1: Check the installation status
Open the organization or repository settings -> GitHub Apps -> [app] and look at the installation status.Expected: You see Suspended with a reason or timestamp.
Step 2: Unsuspend the installation
Choose unsuspend or restore on the installation.Expected: The status changes to active.
Step 3: Verify the app's permissions still hold
Confirm the installation still has the permissions and repository access it needs.Expected: Permissions match what the app requires.
Step 4: Generate a fresh installation token
Request a new installation access token now that the installation is active.Expected: Token issuance succeeds.
Step 5: Retry the failing API calls
Re-run the calls that returned 403.Expected: They return 200 and the app works again.
When this applies
- GitHub App API calls fail with 403 on a suspended installation
- An app that worked yesterday returns forbidden today
- You are debugging GitHub App auth failures
When it doesn't
- The installation is active but calls 403 (check token scopes and expiry)
- The error is 404 (check the installation id)
- The app was never installed (install it first)
Compatibility
GitHub Apps REST API. Installation tokens as of 2026.
Variant phrasings
github app 403 installation suspended
Same condition. Suspension is an installation state; tokens minted against it stay forbidden until unsuspended.
github app forbidden after suspension
Some 403s linger for a minute after unsuspending while caches clear; retry after a short wait.
github app installation blocked 403
Blocked by org policy looks similar. Check whether the org restricts the app versus a true suspension.
Why it happens
Suspending an installation freezes all of its access as a safety control. The API returns 403 for every call because the installation has no rights while suspended, regardless of token validity. Only unsuspending restores access.
Edge cases
- Suspensions can come from GitHub abuse detection; check the account email for notices
- Unsuspending does not retroactively succeed the calls that failed; replay anything important
- Org owners can suspend apps installed by others; coordinate before debugging tokens
If it still fails
- Reproduce with one API call in isolation, outside the agent, to separate platform issues from agent issues.
- Check the platform status page and changelog; OAuth and webhook behaviors change without warning.
- Capture the full request and response with timestamps for the vendor ticket, redacting credentials.
- Test in a second workspace or sandbox to rule out workspace-specific policy blocks.
- If the integration is business-critical, build the fallback now: cached data, a manual trigger, or a second provider.
Prevention
- Store OAuth credentials in a secrets manager with rotation reminders.
- Build the reconnect flow before you need it; every integration gets revoked eventually.
- Log token ages so expiring grants are visible ahead of time.
- Keep a sandbox integration for testing config changes.
- Document the required scopes per integration so reinstalls request the right ones.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_VdTylnJG43hWV6WdZrgxCA