A Multiplayer API error, sent with HTTP 403. Status: the Multiplayer API is in private alpha; this code is part of its published contract.
When
A secret key arrived with an Origin header: it was sent from a browser.
What to do
Never ship the secret key to a browser. Rotate it now, and mint player tokens on your backend instead.
The answer
Every error is a JSON body with a stable error code. Clients act on the codes they know and treat any other code as a failure of its HTTP status, and keep fields they do not know.
{
"error": "secret_key_in_browser",
"detail": "A sentence that is safe to show.",
"next": "Never ship the secret key to a browser. Rotate it now, and mint player tokens on your backend instead.",
"docsUrl": "https://lobbylab.gg/docs/errors/secret_key_in_browser"
}
See also: every error code, the API reference and the docs.