The request could not be satisfied ☁️ AWS

CloudFront: 403 ERROR — The request could not be satisfied

CloudFront refused or couldn’t serve the request — wrong alternate domain/certificate, blocked by origin access settings, a WAF/geo rule, or a disallowed HTTP method.

Seen on: AWS

Meaning

The page includes a Request ID and often a reason: “Bad request. We can't connect to the server for this app or website” (origin/cert issue) or 403 (no CNAME/alternate domain for the host, S3 origin denying OAC, WAF block, method not allowed).

Common causes

  • Host not in the distribution’s Alternate domain names (CNAMEs)
  • S3 origin bucket policy not allowing OAC/OAI
  • WAF or geo restriction blocking
  • POST/PUT not allowed by the behavior’s allowed methods
  • Origin unreachable or TLS mismatch (502 variant)

⚡ Quick fix

  1. Add the domain to alternate domain names with a matching us-east-1 certificate
  2. Update the S3 bucket policy for the distribution’s OAC
  3. Check WAF logs and allowed methods

Detailed fix by platform

IAM

  1. { "Effect": "Allow", "Principal": { "Service": "cloudfront.amazonaws.com" }, "Action": "s3:GetObject", "Resource": "arn:aws:s3:::my-site/*", "Condition": { "StringEquals": { "AWS:SourceArn": "arn:aws:cloudfront::123456789012:distribution/E123ABC" } } }

How to diagnose

  1. Host — In alternate domain names?
  2. Origin — Bucket policy/OAC
  3. WAF — Blocked requests?
  4. Method — Allowed methods

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.