# 500 Kibana API responses resulting from 403 epr.elastic.co responses when trying to add integrations

**URL:** <https://discuss.elastic.co/t/500-kibana-api-responses-resulting-from-403-epr-elastic-co-responses-when-trying-to-add-integrations/370763>\
**Category:** Kibana\
**Created:** [November 19, 2024, 12:02pm UTC](https://discuss.elastic.co/t/500-kibana-api-responses-resulting-from-403-epr-elastic-co-responses-when-trying-to-add-integrations/370763 "2024-11-19T12:02:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![savemetenminutes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/savemetenminutes/32/137199_2.png) [@savemetenminutes](https://discuss.elastic.co/u/savemetenminutes)\
**Post date:** [November 19, 2024, 12:02pm UTC](https://discuss.elastic.co/t/500-kibana-api-responses-resulting-from-403-epr-elastic-co-responses-when-trying-to-add-integrations/370763/1 "2024-11-19T12:02:36Z")

</div>

I keep getting

```auto
{
    "statusCode": 500,
    "error": "Internal Server Error",
    "message": "'403 Forbidden' error response from package registry at https://epr.elastic.co/categories?kibana.version=8.16.0"
}

```

while trying to add integrations within Kibana.  
Looks like some requests do go through though. After waiting for 10-20 minutes I was able to get the list of available integrations and I can see that there is a valid JSON response from the categories endpoint. I haven't been able to get a valid response apart from this exact 403 when trying to go to the APM integration page:

```auto
{
    "statusCode": 500,
    "error": "Internal Server Error",
    "message": "'403 Forbidden' error response from package registry at https://epr.elastic.co/package/apm/8.16.0/"
}

```

Also, image requests seem to result in the same response:

```auto
{
    "statusCode": 500,
    "error": "Internal Server Error",
    "message": "'403 Forbidden' error response from package registry at https://epr.elastic.co/package/aws/2.31.3/img/logo_emr.svg"
}

```

---

<div class="post-metadata">

**Author:** ![Alex\_Salgado-Elastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_salgado-elastic/32/103081_2.png) [@Alex\_Salgado-Elastic](https://discuss.elastic.co/u/Alex_Salgado-Elastic)\
**Post date:** [November 19, 2024, 12:19pm UTC](https://discuss.elastic.co/t/500-kibana-api-responses-resulting-from-403-epr-elastic-co-responses-when-trying-to-add-integrations/370763/2 "2024-11-19T12:19:15Z")

</div>

Hi @savemetenminutes , welcome to our community.

Please test if the machine running Kibana has access:

```auto
curl -v 'https://epr.elastic.co/categories?kibana.version=8.16.0'

```

# DNS Resolution Test

```auto
nslookup epr.elastic.co

```

# Route Test

```auto
traceroute epr.elastic.co

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 19, 2024, 12:39pm UTC](https://discuss.elastic.co/t/500-kibana-api-responses-resulting-from-403-epr-elastic-co-responses-when-trying-to-add-integrations/370763/3 "2024-11-19T12:39:32Z")

</div>

The IP address you are using may be banned.

Check this [post](https://discuss.elastic.co/t/are-you-getting-403s-when-downloading-please-read-here-first/307340) for further details.

---

<div class="post-metadata">

**Author:** ![savemetenminutes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/savemetenminutes/32/137199_2.png) [@savemetenminutes](https://discuss.elastic.co/u/savemetenminutes)\
**Post date:** [November 19, 2024, 7:50pm UTC](https://discuss.elastic.co/t/500-kibana-api-responses-resulting-from-403-epr-elastic-co-responses-when-trying-to-add-integrations/370763/4 "2024-11-19T19:50:14Z")

</div>

> [@Alex\_Salgado-Elastic](#):
>
> `curl -v 'https://epr.elastic.co/categories?kibana.version=8.16.0'`

```auto
# curl -v 'https://epr.elastic.co/categories?kibana.version=8.16.0'
* Trying 34.120.127.130:443...
* TCP_NODELAY set
* Connected to epr.elastic.co (34.120.127.130) port 443 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* successfully set certificate verify locations:
* CAfile: /etc/ssl/certs/ca-certificates.crt
  CApath: /etc/ssl/certs
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384
* ALPN, server accepted to use h2
* Server certificate:
* subject: CN=elastic.co
* start date: Sep 24 22:54:41 2024 GMT
* expire date: Dec 23 22:54:40 2024 GMT
* subjectAltName: host "epr.elastic.co" matched cert's "epr.elastic.co"
* issuer: C=US; O=Let's Encrypt; CN=R11
* SSL certificate verify ok.
* Using HTTP2, server supports multi-use
* Connection state changed (HTTP/2 confirmed)
* Copying HTTP/2 data in stream buffer to connection buffer after upgrade: len=0
* Using Stream ID: 1 (easy handle 0x5570f258a650)
> GET /categories?kibana.version=8.16.0 HTTP/2
> Host: epr.elastic.co
> user-agent: curl/7.68.0
> accept: */*
>
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* old SSL session ID is stale, removing
* Connection state changed (MAX_CONCURRENT_STREAMS == 100)!
< HTTP/2 403
< content-length: 134
< content-type: text/html; charset=UTF-8
< date: Tue, 19 Nov 2024 19:49:12 GMT
< alt-svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
<
* Connection #0 to host epr.elastic.co left intact
<!doctype html><meta charset="utf-8"><meta name=viewport content="width=device-width, initial-scale=1"><title>403</title>403 Forbidden

```

---

<div class="post-metadata">

**Author:** ![savemetenminutes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/savemetenminutes/32/137199_2.png) [@savemetenminutes](https://discuss.elastic.co/u/savemetenminutes)\
**Post date:** [November 19, 2024, 8:16pm UTC](https://discuss.elastic.co/t/500-kibana-api-responses-resulting-from-403-epr-elastic-co-responses-when-trying-to-add-integrations/370763/5 "2024-11-19T20:16:15Z")

</div>

Thanks for pointing this thread out. I did come across it while researching potential causes for this issue, but I couldn't quite make out what the OP was trying to explain. After browsing further down the thread I noticed people were posting their GeoIP info. Since I'm trying to keep my hosting info private should I PM @carly.richmond? How does PMing work with Elastic representatives? Is Slack the preferred channel?

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [November 20, 2024, 6:21am UTC](https://discuss.elastic.co/t/500-kibana-api-responses-resulting-from-403-epr-elastic-co-responses-when-trying-to-add-integrations/370763/6 "2024-11-20T06:21:58Z")

</div>

Hi @savemetenminutes,

Welcome! @leandrojmp is correct that it may be your IP is blocked.

Indeed there is an option to keep your IP private. Let me message you directly and we can investigate.
