Edge Delivery Services Admin API 403 Unauthorized after site creation in Cloud Manager

This article describes the cause of HTTP 403 Unauthorized errors when updating Edge Delivery Services site configuration using the Admin API after creating a site through Cloud Manager and provides recommended steps to resolve the issue.

Description description

Environment

  • Adobe Edge Delivery Services
  • Cloud Manager
  • Admin API

Issue/Symptoms

  • An Edge Delivery Services site is created in Cloud Manager.
  • Attempts to update site configuration through the Admin API fail.
  • Attempts to register secrets through the Admin API fail.
  • The Admin API returns an HTTP 403 Unauthorized error.
  • The error occurs even when authentication is successful.

Cause

The user who creates the site in Cloud Manager does not automatically receive the config-admin role for the site. This is expected behavior for sites created in certain organization contexts and can prevent management of site configuration or administrator roles via the API.

Resolution resolution

Follow the steps below to resolve the issue:

  1. Confirm your site identifier as shown in Cloud Manager under Edge Delivery Services. The identifier format may vary depending on how the site was created.

  2. Ensure you are authenticated by calling the Admin API profile endpoint, https://admin.hlx.page/profile, and confirming a 200 response.

  3. Attempt to access the admin role assignments for your site, for example, https://admin.hlx.page/config/[ organization] /sites/[ site-identifier] /access/admin.json, to verify your current permissions.

  4. If you do not have the config-adminrole and cannot update the site configuration, review your organization’s site creation process:

    • For production workloads, create Edge Delivery Services sites under a dedicated organization where your team can be assigned as organization admins. This allows you to manage site configuration and administrator roles directly.
    • For sites created under a shared organization where you do not have admin rights, follow your organization’s internal process to request assignment of the config-admin role to your user account.
  5. After your user is assigned the config-admin role, verify that you can access the site configuration endpoints without receiving a 403 error.

​‌

recommendation-more-help
experience-cloud-kcs-help-kbarticles