A Multiplayer API error, sent with HTTP 403. Status: the Multiplayer API is in private alpha; this code is part of its published contract.
When
The request's Origin is not in the project's list of allowed origins.
What to do
Add your site's origin (for example https://your-game.example) to the project's origins.
The answer
Every error is a JSON body with a stable error code. Clients act on the codes they know and treat any other code as a failure of its HTTP status, and keep fields they do not know.
{
"error": "origin_not_allowed",
"detail": "A sentence that is safe to show.",
"next": "Add your site's origin (for example https://your-game.example) to the project's origins.",
"docsUrl": "https://lobbylab.gg/docs/errors/origin_not_allowed"
}
See also: every error code, the API reference and the docs.