Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
A Cypress message that mentions “403 Forbidden” does not automatically mean the destination server returned HTTP 403. First determine whether the browser received a real 403 response or Cypress stopped the test because it crossed origins, followed an insecure HTTP link, or could not complete a page load. The fix depends on that evidence: authenticate and authorize a genuine 403, use cy.origin() for a cross-origin page you control, assert an external link’s href when you do not control the destination, and correct HTTPS redirects rather than changing browser-security settings.
What the failure actually means
HTTP 403 is an application or web-server decision: the server understood the request but refuses access. Cypress also reports failures while navigating between origins. That cross-origin failure means Cypress cannot continue communicating with a different superdomain under the current browser origin policy; it is not proof that the destination answered with status 403.
Likewise, Cypress documents an error when an HTTPS page navigates to HTTP. That is an insecure-navigation problem, not an authorization response. Treating every such message as a permissions problem can lead to unsafe or ineffective changes such as disabling web security.
Capture the evidence before changing the test
- Record the exact URL, the command that initiated navigation (
cy.visit(), an anchor click, form submission, or a script redirect), and your Cypress and browser versions. - Open the Cypress command output and browser developer tools. Determine whether a network request received status 403, whether a redirect changed the host or path, or whether Cypress produced an origin/security error before a response was available.
- Save the redirect chain, request method, and relevant response headers where your environment permits. A status from an API or server log is stronger evidence than the wording of a page-load error.
- Try the same exact URL with the same user outside the test. This distinguishes an application access decision from a test-only session, cookie, or origin problem.
Without the request and response, the server-specific reason for a real 403 cannot be identified reliably. Common causes include missing identity, insufficient permissions, a changed host or path after redirect, or an authentication context that was not carried to the destination.
#1 Best Overall
When the destination really returned HTTP 403
Handle a confirmed 403 as an access-control problem until evidence shows otherwise. Check the tested user’s role, the resource’s permissions, required cookies or headers, and whether a redirect moved the request to another host. Do not “fix” it by adding arbitrary retries: retries do not grant permission.
Check a protected endpoint with Basic Authentication
cy.request() performs an HTTP-level request, which is useful when the behavior under test is the response itself rather than a browser rendering. Cypress documents Basic Authentication through the auth option:
cy.request({
url: '/protected',
auth: {
username: Cypress.env('username'),
password: Cypress.env('password'),
},
})
Use your project’s approved secret store and the syntax supported by your installed Cypress version. Never commit real credentials or put them in a spec file.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallUse a token without exposing it
Cypress’s current FAQ documents reading a token with cy.env() and passing it through the request’s headers option. The pattern is:
cy.env('API_TOKEN').then((token) => {
cy.request({
url: '/protected',
headers: {
Authorization: `Bearer ${token}`,
},
})
})
Adapt the environment variable name and authorization scheme to your application. This authenticates the HTTP request; it does not automatically establish the browser state needed by a later click or page navigation.
Rank #2
Inspect a redirect instead of following it
A redirect can remove or change the host, path, cookies, or authentication context. To see the initial response, disable automatic redirect following:
cy.request({
url: '/path',
followRedirect: false,
}).then((response) => {
expect(response.status).to.be.oneOf([301, 302, 303, 307, 308])
cy.log(`Location: ${response.headers.location || ''}`)
})
Then test the redirected URL and its authentication requirements separately. A redirect response is not itself a 403; it may explain why the eventual request loses access.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsWhen Cypress reports a cross-origin failure
You control the second origin
If the test must interact with a destination owned by your project, wrap commands for that origin in cy.origin(). A typical flow is:
cy.visit('https://app.example.test/start')
cy.get('a.account').click()
cy.origin('https://accounts.example.test', () => {
cy.get('input[name="email"]').type('[email protected]')
cy.get('button[type="submit"]').click()
})
The origin passed to cy.origin() must match the destination’s scheme, host, and port. Keep the commands that operate on that page inside the callback. If your sign-in flow passes through several origins, use a separate appropriately scoped block for each origin and keep secrets out of the spec.
You do not control the destination
For a vendor, payment provider, social network, or other third-party link, Cypress recommends checking the link target instead of navigating to the remote page:
Rank #3
cy.get('a.external-link')
.should('have.attr', 'href', 'https://vendor.example/path')
This verifies the contract your application owns and avoids depending on a third party’s uptime, bot checks, cookies, or changing markup. If the test genuinely needs to verify HTTP content, use cy.request() as a separate HTTP test and recognize that it is not browser interaction.
Free tools Windows power users keep installed
One-click scans. No signup required.
HTTPS, HTTP, and authentication redirects
Fix an HTTPS-to-HTTP link
If the test starts on HTTPS and the link or redirect points to HTTP, correct the application URL or redirect to HTTPS. Configure secure cookies so credentials are not exposed during an insecure transition. This condition is distinct from a server returning 403.
Do not make chromeWebSecurity: false your normal 403 remedy. Cypress lists it as a workaround for some cross-origin situations in Chrome-family browsers, not as a way to authorize a request or repair an insecure application link. Prefer an explicit origin strategy or an application fix.
Choose the right SSO strategy
If a sign-in flow itself is what you are testing, exercise the browser flow with the required cy.origin() blocks. If the goal is to test an authenticated API or establish a session efficiently, use an approved request-based login and then validate the resulting application behavior. The choice should follow the behavior under test, not the presence of the word “403” in an error message.
A decision guide for the correct fix
| Evidence or requirement | Preferred approach | Why |
|---|---|---|
| Server response is genuinely 403 | Verify identity, permissions, cookies, headers, and redirect targets | The target application made the access decision |
| Second origin is controlled by your team and must be interacted with | cy.origin() |
Scopes browser commands to the destination origin |
| External destination is not controlled by your team | Assert the anchor’s href |
Tests your contract without relying on a remote page |
| Need status, headers, redirect, or API content | cy.request() |
Direct HTTP evidence, separate from browser navigation |
| HTTPS page points to HTTP | Change the link/redirect to HTTPS and use secure cookies | Removes an insecure-navigation error |
Common symptoms and fixes
“The click failed with 403,” but no 403 appears in Network
Inspect the Cypress error text and command log. If it describes a superdomain or origin policy, stop looking for server permissions and either wrap the controlled destination in cy.origin() or assert href for an external link.
Rank #4
The request works manually but the test is forbidden
Compare the test and manual request’s cookies, login state, host, path, method, and redirect chain. A manual browser may have a session cookie that the test context lacks. Establish authentication through the project’s supported flow, then retry the exact URL rather than a shortened or pre-redirect URL.
Adding an Authorization header did not fix the click
Headers supplied to cy.request() affect that HTTP request; they do not automatically alter a browser anchor navigation. Use a browser login/session flow for UI navigation, or test the endpoint directly with cy.request() when HTTP behavior is the requirement.
Disabling web security made the test pass
Treat this as a warning, not a solution. Re-enable normal security and correct the origin handling, HTTPS configuration, or test boundary. A passing test under a relaxed browser policy may no longer represent a real user’s security model.
The destination displays a bot check or blank page
That is a remote-site behavior, not evidence of authorization. For a third-party link, assert the URL. For a site you own, inspect the response and application logs, then make the test deterministic by controlling the fixture or authentication path.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Or skip the browser setup
If your goal is to capture a page image or PDF rather than test Cypress navigation, ScreenshotNeo makes one request to its screenshot API. It accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each cleanup step can be disabled. Only clean shots are billed: bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and response headers identify the page verdict and billing result.
cURL:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
See the ScreenshotNeo API documentation for parameters and response handling. Its 63 options include full-page lazy-image capture, CSS-selector elements, dark mode, device presets and custom viewports, retina scale, PDF paper and page controls, custom CSS or JavaScript, pre-capture clicks, selector hiding, selector/delay/network-idle waits, request and resource blocking, headers, cookies, user agents, Authorization, timezone and geolocation, transparent backgrounds, resizing, TTL caching, signed image links, asynchronous webhooks, bulk capture of up to 100 URLs per call, usage reporting, and an OpenAPI specification. Existing parameter names used by other screenshot APIs also work to ease migration. An MCP server provides take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients.
The Free plan includes 1,000 screenshots each month with no card. Paid plans start at $5 for 3,000 shots; all features are included on every plan, and annual billing gives two months free. Create a free ScreenshotNeo account.
Reliability and maintenance checklist
- Pin or record the Cypress version and browser used by CI; origin and option behavior can change between versions.
- Keep external-link tests limited to URL assertions and cover vendor content, if needed, in a separately owned contract or HTTP test.
- Log status, redirect location, host, and authentication state for failures without logging secrets.
- Use fixtures or stable test accounts so permission changes are intentional and visible.
- Separate browser-navigation assertions from API authorization assertions; each has different evidence and failure modes.
Frequently Asked Questions
Is every Cypress “403” message an HTTP 403?
No. Confirm a network response with status 403. Cypress can instead be reporting a cross-origin or insecure-navigation failure.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Can I use cy.origin() for a site I do not own?
You can only make that a dependable interaction test when the destination and its behavior are under your control. For an external link, assert the href instead.
Does cy.request() test the same thing as clicking a link?
No. It makes an HTTP request and is appropriate for status, headers, redirects, or API content, while a click tests browser navigation and rendering.
Where should Cypress credentials be stored?
Use the project’s approved secret mechanism, such as environment-backed values, and never commit real usernames, passwords, or tokens to test code.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

