UniFi authorize guest returns 403
A 403 from UniFi can come from three different places: the login, the authorize call after a good login, or something standing in front of the controller. Portal Health and Test Connection tell you which.
Causes, in the order to check them
1. The login is rejectedUniFi
Cloud accounts, accounts with two factor, and wrong passwords are refused at /api/auth/login (UniFi OS) or /api/login (self hosted). Portal Health shows auth with “login rejected (HTTP 403)”. These are not retried.
Test Connection on the location reports the same rejection.
Create a local admin with Network access and no two factor, save it, and test again.
2. The CSRF token never arrivedUniFi
UniFi OS rejects state changing calls without a CSRF token. Some proxies strip the x-csrf-token header. The integration falls back to the token inside the TOKEN cookie; if a proxy also drops cookies, the authorize call fails.
Login succeeds in Test Connection, but authorize attempts fail with a controller error mentioning HTTP 401 or 403.
Pass headers and cookies through the proxy unchanged, or connect through a tunnel that does.
3. The account cannot manage that siteUniFi
A read only role, or an account without access to the venue’s site, can log in but cannot authorize guests there.
Test Connection succeeds but the venue’s site is missing from the returned list.
Give the account Network access to that site, then pick the site again from the list.
4. Something in front of the controller answeredOmada and UniFi
An access gate or a firewall rule on the hostname can answer with its own 403 or a login page before the request reaches UniFi. HTTP 407 specifically comes from the optional egress proxy, not the controller.
Open the controller address from a phone on mobile data. If you see a login page that is not UniFi’s, this is it.
Exempt the API paths from the gate, or publish a second hostname for the integration with the gate off and restrict it another way.
5. Port and console type mismatchUniFi
A self hosted controller on :8443 addressed without its port, or a proxy that confuses console detection, can send the login to the wrong endpoint.
Test Connection reports an unexpected console type.
Include :8443 for self hosted controllers, or set Console Type explicitly to UniFi OS or Legacy.
Reference
| Seen in | Likely source | First check |
|---|---|---|
| Test Connection and Portal Health, kind auth | Login rejected | Local account, no two factor |
| Portal Health only, kind controller | Authorize call rejected | CSRF passthrough, site access |
| A non UniFi login page on the hostname | Access gate or firewall | Exempt the API paths |
| HTTP 407 | Egress proxy credentials | Platform configuration |
Questions
Does the integration retry a 403?
Is the self signed certificate the cause?
Keep reading
Error kinds and codes on this page are the ones the VoqadoWiFi integration records, checked against the code on 7 October 2026.
See every authorization attempt
Portal Health in the free dashboard shows each guest login with its error kind and code. One location and 25 guest logins a month, no card.