# A live key was sent from a browser

> 403 live_key_in_browser

A request a browser made — one carrying `Origin` or `Sec-Fetch-Site` — came with a live key. A page anybody can open must never hold a live key, so it is refused even from the developer website.

## What to do

Call the API from your server. A test key works from the developer website's Try it.

## Retrying

No: the same request gets the same answer until something is changed.
