RocketChat/Rocket.Chat · error · Meteor.Error

error-not-allowed

error-not-allowed

Error message

Not Allowed

What it means

Meteor error error-not-allowed thrown by GET channels.online when the authenticated user cannot access the resolved channel (canAccessRoomAsync returns false for this.user). The channel exists and matches the query, but the caller has no membership/visibility rights to see who is online in it — public channels require nothing special, but the room found may be one the user cannot read.

Solutions

  1. Have the calling user join the channel (channels.join) or get added, then retry
  2. Verify access first with GET channels.info using the same credentials — it applies the same room-access rules
  3. For bots, grant a role with the appropriate room visibility or use an admin-scoped token for read-only telemetry
Defensive patterns

Strategy: validation

Validate before calling

try {
  await GET('/api/v1/channels.info', { roomId }); // same access rules
} catch {
  throw new Error('No access to channel; join it before querying online users');
}

Try / catch

try { await GET('/api/v1/channels.online', { _id: roomId }); } catch (e) {
  if (e.error === 'error-not-allowed') { /* prompt join or use privileged token */ }
}

Prevention

When it happens

Trigger: GET /api/v1/channels.online?_id=<channelId> (or with a query) where the user is not a member of a channel whose access rules exclude them (e.g. broadcast/teamsRoom restrictions, or the room matched by a loose query is not actually accessible).

Common situations: Bot tokens querying channels they were never invited to; query filter matching an unexpected room (missing t:'c' nuance aside, a broad query can resolve to a room the bot cannot see); user was kicked between list load and the online fetch.

Understand the failure class

Background: "You do not have permission" / 403 Forbidden errors: authenticated but not allowed — causes and fixes across open-source libraries — this error's family across 31 libraries.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@e4b8178b20 (2026-09-08). Data as JSON: /api/errors/bd1aa371aece302f. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/api/v1/channels.ts:1735

		const { _id } = this.queryParams;

		if ((!query || Object.keys(query).length === 0) && !_id) {
			return API.v1.failure('Invalid query');
		}

		const filter = {
			...query,
			...(_id ? { _id } : {}),
			t: 'c',
		};

		const room = await Rooms.findOne(filter as Record<string, any>);
		if (!room) {
			return API.v1.failure('Channel does not exists');
		}

		if (!(await canAccessRoomAsync(room, this.user))) {
			throw new Meteor.Error('error-not-allowed', 'Not Allowed');
		}

		const hidden = await getUsersHiddenFrom(this.userId);

		const online: Pick<IUser, '_id' | 'username'>[] = filterHiddenUsers(
			await Users.findUsersNotOffline({
				projection: { username: 1 },
			}).toArray(),
			hidden,
		);

		const onlineInRoom = await Promise.all(
			online.map(async (user) => {
				const subscription = await Subscriptions.findOneByRoomIdAndUserId(room._id, user._id, {
					projection: { _id: 1, username: 1 },
				});
				if (subscription) {
					return {

View on GitHub (pinned to e4b8178b20)