# 403 when connecting from Server to pinecone

**URL:** <https://community.pinecone.io/t/403-when-connecting-from-server-to-pinecone/8421>\
**Category:** Support\
**Created:** [October 13, 2025, 9:23am UTC](https://community.pinecone.io/t/403-when-connecting-from-server-to-pinecone/8421 "2025-10-13T09:23:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![klaus](https://sea2.discourse-cdn.com/flex020/user_avatar/community.pinecone.io/klaus/32/3887_2.png) [@klaus](https://community.pinecone.io/u/klaus)\
**Post date:** [October 13, 2025, 9:23am UTC](https://community.pinecone.io/t/403-when-connecting-from-server-to-pinecone/8421/1 "2025-10-13T09:23:50Z")

</div>

Hello!  
I’m on a free plan and tried to use Pinecone with my self-hostet n8n server. My server runs on a Hetzner shared server. When I try to access the index via CURL using a API key it works from my local workstation, but I get a 403 on my server. I tried a command from DOCs:  
curl -X GET “[https://api.pinecone.io/indexes”](https://api.pinecone.io/indexes%E2%80%9D) \  
-H “Api-Key: xxxxx”  
My local workstation gets a reply with my demo index.

But my Server gets:

403 Forbidden
# Error: Forbidden

## Your client does not have permission to get URL `/indexes` from this server.

## 

Does anyone know how to solve this issue?  
Thanks in advance!

---

<div class="post-metadata">

**Author:** ![jocelyn](https://sea2.discourse-cdn.com/flex020/user_avatar/community.pinecone.io/jocelyn/32/1653_2.png) [@jocelyn](https://community.pinecone.io/u/jocelyn)\
**Post date:** [October 13, 2025, 6:04pm UTC](https://community.pinecone.io/t/403-when-connecting-from-server-to-pinecone/8421/2 "2025-10-13T18:04:15Z")

</div>

hi @klaus

403 typically means youve either exceeded a quota, or hit deletion protection

Since you’re encountering a 403 Forbidden error when accessing Pinecone’s API from your Hetzner server, but the same request works from your local workstation it sounds like a client error (again, indicating permission issues)

Since the same API key works from your local machine, the issue might be related to your server environment rather than the API key itself.

Here are the most likely causes and solutions, to help you hone in:

**1. Check your API key permissions**  
Ensure your API key has the necessary permissions for the operation you’re trying to perform . Since you’re using a free plan, _verify you haven’t exceeded the Starter plan limits_, which include 5 serverless indexes per project and 2 GB of serverless index storage per project

**2. Verify your server’s network configuration**  
The fact that it works locally but not from your Hetzner server suggests a network-level issue. Check if your server has any firewall rules or network restrictions that might be blocking outbound HTTPS requests to Pinecone’s API endpoints.

**3. Confirm you’re using the correct API endpoint**  
Make sure you’re using the correct global control plane endpoint `https://api.pinecone.io/indexes` as shown in your command. This is the proper format for control plane operations.

**4. Check for billing issues**  
Although you mentioned you’re on the free plan, verify your billing status in the console to ensure there are no account-level restrictions.

If none of these resolve the issue, I recommend checking out these resources:

- [Error handling](https://docs.pinecone.io/guides/production/error-handling#understand-error-types)
- [Pinecone Database limits](https://docs.pinecone.io/reference/api/database-limits#object-limits)

You can also drop in to our [official Discord](https://discord.gg/qU3yVdqRda) to chat about the issue

---

<div class="post-metadata">

**Author:** ![klaus](https://sea2.discourse-cdn.com/flex020/user_avatar/community.pinecone.io/klaus/32/3887_2.png) [@klaus](https://community.pinecone.io/u/klaus)\
**Post date:** [October 14, 2025, 11:23am UTC](https://community.pinecone.io/t/403-when-connecting-from-server-to-pinecone/8421/3 "2025-10-14T11:23:38Z")

</div>

Thanks for your response.  
I’ve double-checked the API key, endpoint, and quota — everything is within limits and works perfectly from my local machine.

The issue is reproducible only from my Hetzner (AS24940) shared server:

- DNS resolution and TLS handshake complete successfully.

- `curl -v https://api.pinecone.io/indexes` returns an immediate HTTP/2 403 with a standard Google Frontend (GFE) HTML page.

- The same API key and request from a local or AWS host return 200 OK.

- Data-plane endpoints (e.g. `https://<index-name>.svc.aped-4627-b74a.pinecone.io/...`) work fine from Hetzner — only the control-plane endpoint is blocked.

This suggests that requests from Hetzner IP ranges are being rejected at Google’s edge/WAF level rather than by Pinecone’s application layer.

Could you please confirm whether Pinecone’s control-plane endpoints intentionally block certain hosting ASNs (like Hetzner Online) or if there’s a chance to whitelist specific IPs?  
My IPv6 prefix is `2a01:4f8:c17:918e::/64` (Hetzner Online GmbH, Germany).

Thanks for checking this — the routing and TLS traces clearly show the block originates upstream of my host firewall.

---

<div class="post-metadata">

**Author:** ![silas](https://sea2.discourse-cdn.com/flex020/user_avatar/community.pinecone.io/silas/32/1337_2.png) [@silas](https://community.pinecone.io/u/silas)\
**Post date:** [October 14, 2025, 7:25pm UTC](https://community.pinecone.io/t/403-when-connecting-from-server-to-pinecone/8421/5 "2025-10-14T19:25:39Z")

</div>

Hi @klaus ,

I suspect you’re right that GCP is blocking your IP for some reason. We’ll need to open a case with them to troubleshoot, and will follow-up with you here when we know more.

Thanks,

Silas - engineering

---

<div class="post-metadata">

**Author:** ![klaus](https://sea2.discourse-cdn.com/flex020/user_avatar/community.pinecone.io/klaus/32/3887_2.png) [@klaus](https://community.pinecone.io/u/klaus)\
**Post date:** [October 15, 2025, 8:51am UTC](https://community.pinecone.io/t/403-when-connecting-from-server-to-pinecone/8421/6 "2025-10-15T08:51:14Z")

</div>

Great, thanks for your help!
