Skip to main content
Developer Communities Admin
Community Manager
September 15, 2026

DELETE SSO API Call Returns 403 – But Works in Postman

  • September 15, 2026
  • 0 replies
  • 1 view

Originally posted by Sukal Mondal on October 20, 2025 at 3:40 PM.

 

DELETE SSO API Call Returns 403 – But Works in Postman

 

A developer reported that a DELETE SSO call worked fine through Postman, but returned a 403 Forbidden when triggered via MuleSoft. Cloudflare was blocking the request, even though the endpoint and payload were identical.

 

💡 Expert Tip

This kind of mismatch often points to differences in headers, tokens, or request signatures between tools. MuleSoft or other middleware might be sending an extra header or using an outdated token format that Cloudflare flags.

Quick things to check:

  • Compare full request headers from both Postman and MuleSoft.
  • Validate
  • Content-Type
  • and
  • Authorization
  • fields exactly match.
  • Ensure TLS/SSL negotiation isn’t being altered by your middleware.

 

Open Questions for the Community

  • Have you seen Cloudflare blocking requests from certain middleware before?
  • What’s your preferred way to debug 403s when the same call works elsewhere?
  • Any best practices for aligning API gateway security with integration tools?

Let’s trade tips on building secure, reliable API flows across tools.