vultr-cli: 403 Forbidden - API access not enabled for the user
Fixes vultr-cli returning 403 for sub-users whose API access is disabled. Use when the key is valid but the API rejects calls with Forbidden. The fix is enabling API access for that user in the Vultr portal (Account, Users). Not for invalid keys (401).
The API key is fine, but API access is switched off for that user. In the Vultr portal go to Account, Users, edit the user, and click Enable API under User API Key. Until that switch is on, every call 403s no matter how valid the key is.
$ vultr-cli account get
{"error": "Forbidden", "status": 403}Fix
- Log into the Vultr customer portal as the account owner or an admin.
- Go to Account, then Users under Other. Select the user and click the Edit User icon.
- Click Enable API under User API Key. Save.
Expected: the user's API status shows enabled.
- Retry the CLI:
vultr-cli account getExpected: account details print.
When this applies
- 403 Forbidden with a key that was just created and is correctly configured.
- The key belongs to a sub-user rather than the account owner.
When it does NOT apply
- 401 Invalid API key: the key itself is bad; regenerate it.
- 403 right after enabling IP allowlist changes: the runner's IP is blocked, different cause.
Compatibility
- vultr-cli against the Vultr API v2; portal user management.
Why it happens
Vultr gates API usage per user in addition to key validity. Sub-users are created API-disabled by default, so a freshly minted key for such a user authenticates (the key exists) but is refused at the authorization step.
Edge cases
- Only admins can flip the switch; if you are the sub-user, ask the account owner.
- Disabling and re-enabling can be used to quickly cut off a compromised sub-user key.
- The main account owner's key never hits this; if the owner 403s, look at IP allowlists instead.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.