RocketChat/Rocket.Chat · error · Error
error-not-allowed
Error message
error-not-allowed
What it means
Thrown by GET /api/v1/livechat/room.join when canAccessRoomAsync(room, user) resolves false. The room exists, is open, and MAC limits allow the join, but this particular authenticated user is not permitted to access this omnichannel room (despite holding the route-level view-l-room permission).
Solutions
- Give the user access: add them to the room's unit/department or assign the appropriate livechat roles/permissions
- Verify with an admin what canAccessRoom evaluates for that user/room pair (units, departments, roles)
- If broad monitoring is intended, grant the permission set that omnichannel monitors use (e.g. view-livechat-rooms / monitor arrangements) instead of relying on join
Defensive patterns
Strategy: try-catch
Try / catch
try { await joinRoom(roomId); } catch (e) { if (e.message === 'error-not-allowed') { showNeedsAccessMessage(roomId); return; } throw e; } Prevention
- Pre-assign agents to the units/departments whose rooms they must join
- Do not assume view-l-room grants access to every room — units/departments scope it
- Use monitor-oriented permission sets for oversight workflows
When it happens
Trigger: An agent outside the room's unit/department restrictions joining a conversation scoped to another unit; users without the livechat-agent role or without membership trying to join; deployments using livechat delegation/units that scope room visibility.
Common situations: Multi-unit installs where agents see only their unit's conversations; agents attempting to join inquiries routed to a department they do not belong to; custom agent desks assuming all agents can join any open room.
Understand the failure class
Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.
Related errors
AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18).
Data as JSON: /api/errors/bf9c5997d81c3f4b.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/server/api/v1/omnichannel/room.ts:430
throw new Error('error-invalid-user');
}
const room = await LivechatRooms.findOneById(roomId);
if (!room) {
throw new Error('error-invalid-room');
}
if (!room.open) {
throw new Error('room-closed');
}
if (!(await Omnichannel.isWithinMACLimit(room))) {
throw new Error('error-mac-limit-reached');
}
if (!(await canAccessRoomAsync(room, user))) {
throw new Error('error-not-allowed');
}
await addUserToRoom(roomId, user);
return API.v1.success();
},
},
);
API.v1.addRoute(
'livechat/room.saveInfo',
{ authRequired: true, permissionsRequired: ['view-l-room'], validateParams: isLiveChatRoomSaveInfoProps },
{
async post() {
const { roomData, guestData } = this.bodyParams;
const room = await LivechatRooms.findOneById(roomData._id);
if (!room || !isOmnichannelRoom(room)) {
throw new Error('error-invalid-room');View on GitHub (pinned to b2c16d5842)