# Fix Braintree client token generation returning 403 forbidden

## TL;DR
A 403 on client token generation means the API credentials are wrong, lack permission, or are scoped to the wrong environment. Verify you are using the right environment's keys with the right merchant id, then regenerate. Sandbox keys against production always 403.

## The error
```text
Braintree client token generation failed
403 Forbidden: Not authorized to generate client token
```

## Use this skill
Agent? Search Vectle for this error:
```bash
curl -s "https://vectle.com/api/v1/search?q=braintree client token generation 403 forbidden error"
```

## Fix it

### Step 1: Confirm the environment

```bash
Check whether your code points at sandbox or production, and use that environment's keys.
```

Expected: The environment matches the keys.

### Step 2: Verify the merchant id

```bash
Compare the merchant id in your config with the Braintree control panel.
```

Expected: They match.

### Step 3: Check the API key permissions

```bash
In the Braintree control panel, confirm the API key is active and permitted for client token generation.
```

Expected: The key is active with the right permissions.

### Step 4: Regenerate if in doubt

```bash
Generate fresh API credentials and update your config.
```

Expected: The new credentials are stored and active.

### Step 5: Retry token generation

```bash
Request a client token again.
```

Expected: Generation returns 200 with a token.

## When this applies

- Braintree client token generation returns 403
- Payments worked in sandbox but fail in production
- You just rotated API credentials

## When it doesn't

- Token generation works but the drop-in fails (check the client integration)
- The error is 401 (check the key values themselves)
- Transactions fail after tokenizing (check the transaction call)

## Compatibility

Braintree server SDKs. Sandbox and production environments.

## Variant phrasings

### braintree 403 client token

Same failure. Environment mismatch is the top cause.

### braintree not authorized generate token

Not authorized points at key permissions or a wrong merchant id.

### braintree sandbox keys production 403

Cross-environment keys always fail. Keep the pairs separate and labeled.

## Why it happens

Braintree scopes every credential to one environment and merchant. A 403 means the credential is not entitled to mint client tokens in the context it was used: wrong environment, wrong merchant id, or a key whose permissions were trimmed. The credentials are valid somewhere, just not here.

## Edge cases

- Client tokens are short-lived; generate them per checkout session, not per deploy
- The public key in client config must pair with the server credentials
- Revoked keys 403 immediately; rotation without updating the app breaks checkout instantly

## If it still fails

- Reproduce in test mode with test cards before touching live config.
- Read the full API error object; the code and decline code name the next step.
- Check the provider status page; payment API incidents look like integration bugs.
- Never retry live charges blindly; verify state first and use idempotency keys.
- For money-movement confusion, reconcile against the dashboard before writing code.

## Prevention

- Exercise the full payment flow in test mode on every deploy.
- Alert on failed payment webhooks, not just API errors.
- Keep idempotency keys on every charge-creating call.
- Reconcile payouts against the dashboard on a schedule.
- Document the retry and dunning policy so agents and humans agree.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_jzIOV-e_Zqltg1nv6Od7Sw
