Fix Tengine 403 Forbidden error
2026-09-29
A 403 Forbidden from Tengine means one thing: the server decided you are not allowed to see this — and unlike a 404, it is usually a deliberate decision by a config rule. I have chased this error in four different disguises; here they are, in the order to check.
Cause 1 — Missing index file
The most common cause. You browse to the directory root, Tengine looks for the index file, finds none, and directory listing is off (default), so it returns 403:
server {
root /www/wwwroot/yourdomain;
index index.html;
}
Check the file exists and the name matches: ls -la /www/wwwroot/yourdomain/. A file named Index.html instead of index.html will not match on Linux.
Cause 2 — File/directory permissions
Tengine’s worker user needs read on the file and execute (search) on every parent directory:
chmod 755 /www/wwwroot/yourdomain
chmod 644 /www/wwwroot/yourdomain/index.html
If files were uploaded with 600 permissions, you get an instant 403.
Cause 3 — An allow/deny rule blocked you
Check for deny directives or a geo block. The classic surprise is allow all; being overwritten by a later deny all;, or a firewall-level rule:
grep -r "deny\|allow" /etc/nginx/conf.d/yourdomain.conf
Cause 4 — Request body too large
Sometimes what looks like a 403 on upload is really the 413 limit being reported oddly by the client. If the 403 only happens on upload paths, check that first.
Diagnose with the error log
The log tells you exactly which of the four it is:
tail -20 /usr/local/tengine/logs/error.log
directory index of "/www/..." is forbidden→ Cause 1Permission denied→ Cause 2access forbidden by rule→ Cause 3
Summary
Missing index, permissions, or an access rule — the error log names the culprit in one line. If your site serves static files fine but your API routes 403, check the proxy config for stray deny rules or move on to my 502 guide for upstream issues.