> Source: [sk174606](https://support.checkpoint.com/results/sk/sk174606)

# sk174606 - "You don't have permission to access this resource" when connecting to the API documentation on the Management Server

| Property | Value |
|----------|-------|
| Solution ID | sk174606 |
| Date Created | 2021-07-20 |
| Last Modified | 2025-01-20 |
| Technical Level | General |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |

## Symptoms

- Web browser shows:

```

Forbidden
You don't have permission to access this resource
```

when connecting to the API documentation on the Management Server at:  
`https://<IP Address of Management Server>/api_docs`

## Cause

By default, the access is allowed only within the Management Server itself.

## Solution

Follow one of the applicable procedures to configure the applicable access to the API documentation on the Management Server - either in SmartConsole, or with API commands:

### In SmartConsole:

1. Connect with SmartConsole to the Security Management Server / applicable Domain Management Server.

2. From the left navigation panel, click **Manage \& Settings**.

3. In the middle section, click **Blades**.

4. In the **Management API** section, click **Advanced Settings**.

5. Select the applicable option:

   * To allow access from all IP Addresses that you configured as trusted GUI clients, select:

     **All IP Addresses that can be used for GUI clients**
   * To allow access from all IP Addresses, select:

     **All IP Addresses**
6. Click **OK**.

7. Publish the Session.

8. Restart the API Server on the Management Server:

   1. Connect to the command line on the Management Server.

   2. On a Multi-Domain Server, go to the context of the applicable Domain Management Server:

      **`mdsenv <`*IP Address or Name of Domain Management Server*`>`**
   3. Restart the API Server:

      **`api restart`**

      The output of this command must show:

      `API started successfully`
   4. Examine the API Server status:

      **`api status`**

<br />

### On the Command Line:

1. Connect to the command line on the Management Server.

2. Log in to the Expert mode.

3. Configure the applicable access:

   See: <https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-api-settings>
   * To allow access from all IP Addresses that you configured as trusted GUI clients:

     **`mgmt_cli -r true set api-settings accepted-api-calls-from "all ip addresses that can be used for gui clients" --domain 'System Data'`**
   * To allow access from all IP Addresses:

     **`mgmt_cli -r true set api-settings accepted-api-calls-from "all ip addresses" --domain 'System Data'`**

   **Notes:**
   * To allow access from the Management Server only, run:

     **`mgmt_cli -r true set api-settings accepted-api-calls-from "server only" --domain 'System Data'`**
   * The output of this command must show:

     `"Publish operation" succeeded (100%)`
4. Load the new settings:

   **`api reconf`**

   The output of this command must show:

   `API reconfigured successfully`
5. Examine the API Server status:

   **`api status`**

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
