# `origin_not_allowed`

A Multiplayer API error, sent with HTTP 403. Status: the Multiplayer API is in private alpha; this code is part of its published contract.

## When

The request's Origin is not in the project's list of allowed origins.

## What to do

Add your site's origin (for example https://your-game.example) to the project's origins.

## The answer

Every error is a JSON body with a stable `error` code. Clients act on the codes they know and treat any other code as a failure of its HTTP status, and keep fields they do not know.

```json
{
  "error": "origin_not_allowed",
  "detail": "A sentence that is safe to show.",
  "next": "Add your site's origin (for example https://your-game.example) to the project's origins.",
  "docsUrl": "https://lobbylab.gg/docs/errors/origin_not_allowed"
}
```

See also: [every error code](/docs/errors), [the API reference](/docs/api) and [the docs](/docs).
