Frequently Asked Questions

FAQ's » MTD ITSA FAQ's » HMRC MTD ITSA HTTP status 403 Forbidden

HMRC MTD ITSA HTTP status 403 Forbidden

HMRC server may return an error 403 (Forbidden). Software will display a message: Your submission has not passed HMRC server validation. It has returned an error message 403 Forbidden.

CLIENT_OR_AGENT_NOT_AUTHORISED when Making Tax Digital MTD commercial software is communicating with HMRC MTD ITSA service.

Symptoms:

When customer is attempting to submit or retrieve Making Tax Digital MTD ITSA data to and from HMRC, customer may get a message in the MTD ITSA software:

HMRC server has returned an error message:
HTTP status: 403 (Forbidden),
Code: CLIENT_OR_AGENT_NOT_AUTHORISED
The Trader or Agent has not authorised the software to interact with HMRC MTD system. Run ITSA Digital Authorisation process again and authorise access for the software.
This issue is not caused by Andica software, the software is simply relaying the response received from HMRC's server.

Cause:

HMRC MTD ITSA service has returned an error message HTTP status 403
CLIENT_OR_AGENT_NOT_AUTHORISED as it is not able to get ITSA obligation data as the client or an agent is not authorised.

This message is returned by HMRC when the client or agent is not authorised to submit or request MTD ITSA data.

Most likely reasons are:

  • Client/Agent isn’t using the credential that has the MTD enrolment attached to it i.e. signed up for MTD with one credential but log into software with a different credential.

  • If the agent is a supporting agent they are only permitted you use certain API’s, certain APIs will return the 403.

  • Client/Agent not authorised error.

  • Client is not signed up for MTD.

  • Client/Agent may have signed into their software prior to signing up to MTD. The way around this is to sign out and sign back into software.

  • Incorrect NINO suffix entered in MTD software.

Solution:

This guidance outlines the key checks and actions that can be done when encountering a “403 Client/Agent Not Authorised” error message prior to referring the incident.

  1. Verify Agent–Client Relationship Mapping
    Confirm that existing agent–client relationships have been successfully transferred from Self Assessment to the Agent Services Account (ASA). Please refer to the attached slides detailing the mapping process.

  2. Confirm Correct Government Gateway Credentials
    Ensure that the customer or agent is signed in using the Government Gateway user ID that has the relevant MTD enrolment attached.
    Using credentials without the correct enrolment will result in a 403 not authorised error .

  3. Check Agent Role (Main vs Supporting Agent)
    Determine whether the agent is acting as a main agent or a supporting agent.
    Supporting agents have restricted access and are only permitted to use specific APIs.
    Attempts to access restricted APIs will trigger a 403 not authorised error.

  4. Confirm MTD Sign-Up Status
    Verify that the customer has successfully signed up to Making Tax Digital (MTD).
    If sign-up is incomplete, access to MTD services will be denied.

  5. Check Software Login Sequence
    If the customer or agent accessed their software before completing MTD sign-up, they must sign out of the software, and sign back in again after enrolment is confirmed.

  6. Validate National Insurance Number (NINO)
    Ensure that the correct NINO suffix has been entered in the software. Incorrect suffix entries can prevent successful authorisation

If the issue persists, you will need to contact HMRC's Online Services helpdesk. HMRC have announced that before contacting HMRC please ensure the Agent Service Account credentials are being used, and not legacy SA credentials. To aid their investigations they would ask you to provide full details of the credentials being used within the referral. HMRC will also look to see what improvements can be made to external guidance.

Software Message (Symptoms) HMRC Error scenario HMRC Error code Cause Solution
HMRC server has returned an error message:
HTTP status: 403 (Forbidden),
Code: HTTPS_REQUIRED
Request done with HTTP
Request done with HTTP HTTPS_REQUIRED A request to the HMRC is done with HTTP Please contact your software provider for further help.
HMRC server has returned an error message:
HTTP status: 403 (Forbidden),
Code: RESOURCE_FORBIDDEN
The OAuth token's application is not subscribed to the API.
The OAuth token's application is not subscribed to the API RESOURCE_FORBIDDEN The OAuth token's used in this application is not subscribed to the API Please contact your software provider for further help.
HMRC server has returned an error message:
HTTP status: 403 (Forbidden),
Code: INVALID_SCOPE
The scope of the OAuth token is not sufficient to access the INVALID_SCOPE.
The scope of the OAuth token is not sufficient to access the INVALID_SCOPE INVALID_SCOPE The scope of the OAuth token is not sufficient to access the INVALID_SCOPE Please contact your software provider for further help.
HMRC server has returned an error message:
HTTP status: 403 (Forbidden),
Code: FORBIDDEN
Supplied OAuth token not authorised to access data for given tax identifier(s)
Supplied OAuth token not authorised to access data for given tax identifier(s) FORBIDDEN Supplied OAuth token not authorised to access data for given tax identifier(s) Please contact your software provider for further help.

Adding existing Self Assessment authorisations

User on ASA homepage clicks: Add existing Self Assessment authorisations to this account

MTD ITSA Self Assessment Authorisations
Top