403 error in API connection after the 0.56.0 update

WHAT IS THE BUG

When trying to connect to Anytype local API, it returns a 403 error.

HOW TO REPRODUCE IT

  1. Open an app that uses the Anytype API.
  2. Observe the console output.

THE EXPECTED BEHAVIOR

The HTTP code must be 200.

ADDITIONAL CONTEXT

wAulBrEsFm

TECHNICAL INFORMATION

OS version: win32 x64 10.0.26200
App version: 0.56.0
Build number: build on 2026-07-17 23:05:35 +0000 UTC at #d03cedda1073744beab396559622e7847a955f1f
Library version: v0.50.17
Anytype Identity: A9cpgx7Qc9wgjor83ktFiDxGM2K75TAqM4yQqdbKWYwm7kGr
Analytics ID: bcb499b1-f8bd-4764-99b9-44888bcebf37
Device ID: 12D3KooWECpmjebChgLtxf5axpEa3ALbvaDD3Cr46tkq5TwGPjFp
Ethereum Address: 0xE3c22Cc1F6cFe6A2aE52dB0cB3DA265b09e5Dd7f

Thanks for reporting.

Thanks for reporting! Since this runs in a browser — where is the page served from? http://localhost:, a hosted site, or an HTML file opened directly (file://)?

In 0.56.0 we started checking the browser’s Origin header on the local API. Previously any website you had open could send requests to it and act on them, including the unauthenticated pairing endpoints — so we now reject untrusted origins, and added a lockout after repeated failed pairing codes. Native clients (curl, Python, etc.) send no Origin and are unaffected.

Depending on your case:

  • http://localhost / 127.0.0.1 — trusted, should still work
  • hosted site — add its origin to ANYTYPE_API_ALLOWED_ORIGINS env var (make sure it is passed to the app or set globally)
  • file:// — the browser sends Origin: null, which we can’t allow (any page can forge it), so the env var won’t help; serve the file from a local http server instead

We plan to expose the allowed origins in app settings so this doesn’t need an env var.

Hi. This is a browser extension (Save to Anytype). In our case, I think we will need to add the environment variable. I will test and report.

Are you the maintainer of this extension? I think we should reconsider the security solution we made.

  • We should only send Origin for non-authenticated methods (the ones used to show the challenge).
  • We can add legitimate extensions to the whitelist to allow the desktop app to request the code challenge.

I created the issue in our ticket system to cover this. Thanks for reporting!

Yes, me and my friend are the maintainer of this extension. Then I’m waiting for now. I hope the new method will be published soon.

Hi @requilence Will our issue be resolved in the V0.56.1 update?

Unfortunately, it was not included in 0.56.1. The scope of change is quite big and It needs more time to carefully test so it will not break the compatibility with existing integrations.

I think it needs 2-3 more days and will be included in 0.56.2

Ok, thank you for answer.