vercel/next.js · error · Error

`forbidden()` is experimental and only allowed to be…

Error message

`forbidden()` is experimental and only allowed to be enabled when `experimental.authInterrupts` is enabled.

What it means

Feature gate on the forbidden() interrupt: calling it requires experimental.authInterrupts to be enabled in next.config because the auth-interrupt rendering flow is experimental. The throw fires when the function is invoked in a project without that flag set.

Solutions

  1. Enable experimental.authInterrupts in next.config.js before calling forbidden(), or remove the forbidden() call.
Defensive patterns

Strategy: validation

When it happens

Trigger: forbidden() is called without enabling experimental.authInterrupts.

Common situations: Using the forbidden() API in app router code while the authInterrupts flag is off in next.config.

Understand the failure class


AI-assisted analysis of vercel/next.js@0eb3775416 (2026-08-19). Data as JSON: /api/errors/aa38e78784bd18bd. Report an issue: GitHub.

Appendix: source

Thrown at packages/next/src/client/components/forbidden.ts:24

// TODO: Add `forbidden` docs
/**
 * @experimental
 * This function allows you to render the [forbidden.js file](https://nextjs.org/docs/app/api-reference/file-conventions/forbidden)
 * within a route segment as well as inject a tag.
 *
 * `forbidden()` can be used in
 * [Server Components](https://nextjs.org/docs/app/building-your-application/rendering/server-components),
 * [Route Handlers](https://nextjs.org/docs/app/building-your-application/routing/route-handlers), and
 * [Server Actions](https://nextjs.org/docs/app/building-your-application/data-fetching/server-actions-and-mutations).
 *
 * Read more: [Next.js Docs: `forbidden`](https://nextjs.org/docs/app/api-reference/functions/forbidden)
 */

const DIGEST = `${HTTP_ERROR_FALLBACK_ERROR_CODE};403`

export function forbidden(): never {
  if (!process.env.__NEXT_EXPERIMENTAL_AUTH_INTERRUPTS) {
    throw new Error(
      `\`forbidden()\` is experimental and only allowed to be enabled when \`experimental.authInterrupts\` is enabled.`
    )
  }

  const error = new Error(DIGEST) as HTTPAccessFallbackError
  ;(error as HTTPAccessFallbackError).digest = DIGEST
  throw error
}

View on GitHub (pinned to 0eb3775416)