FME Flow Connections Runtime Error: Unauthorized request by user due to lack of proper permissions

Aaron Hillier
Aaron Hillier
  • Updated

Consideration

When you run a workspace on FME Flow that uses a web or database connection, the translation may fail and show an error in the job log. This can happen whether you run the workspace directly, on a schedule, through an Automation, or via a Flow App, webhook, or REST API request.

Example error message:

Unauthorized request by user due to lack of proper permissions

Why This Happens

This error means the user account or API token used to submit the workspace does not have access permissions to the connection or connections used in the workspace. Common causes include:

  • Backup and restore: FME Flow was restored from a backup of an earlier version, and connection permissions didn't carry over. This can happen when you move to a newer version of FME Flow because of security improvements.
  • Connection not shared: Another user shared the workspace with you but did not also share the connection it uses.
  • Connection not published: If you own the workspace, the connection may not have been included when you published the workspace to FME Flow.
  • Unauthorized access attempt: A user manually enters the name of a connection they do not have permission to use.
  • Windows authentication: On FME Flow, Windows authentication to a database uses the account running the FME Flow Engine service, not the account running the workspace.

How to Resolve It

Ensure that the user account or API token submitting the workspace has access permissions to the connection or connections used in the workspace. The right option depends on how the workspace runs and whether you own it.

Option 1: User Permissions (Running a Workspace, Schedule, or Automation)

To confirm the issue is caused by a missing user permission, go to Connections & Parameters and open the Web Connections or Database Connections page. Check whether the connection is listed.

If the connection is listed, contact Safe Software Support for further assistance. If it is not listed, or you do not have access to check, use one of the following methods.

Request Access From an Administrator

Ask a user with administrator privileges to grant access to the connection:

  1. Go to Admin > User Management > Users.
  2. Find the user account and click it to edit permissions.
  3. Under Permissions, locate Connections and click the drop-down arrow next to Show Connections.
  4. Find the connection used in the workspace. Click the drop-down under Summary and select Full Access.
  5. Click Save.

An administrator grants a user access to a connection.

Request Sharing From the Workspace Owner

If another user shared the workspace with you, ask them to also share the connection:

  1. Go to the Web Connections or Database Connections page under Connections & Parameters.
  2. Click the Share with Others button.
  3. Find the username, select Full Access, then click Share.

Ask another user to share their connection with you.

Create a New Connection

If you prefer not to depend on another user's connection, create your own, tied to your own credentials. Open FME Flow and go to Connections & Parameters. See the Database Connections and Web Connections documentation for instructions. When configuring the workspace to run, set the Connection user parameter to the new connection.

Create a new connection in FME Flow.

Publish the Connection

If you own the workspace, you may have opted out of publishing the connection.

  1. Open FME Workbench and click Publish to FME Flow.
  2. On the Upload Connections page of the publishing wizard, enable the checkbox for the connections used in the workspace.

Upload connections when publishing a workspace to FME Flow.

Alternatively, follow the steps in Request Access From an Administrator or Create a New Connection above.

Option 2: API Token Permissions (Flow Apps, Webhooks, or REST API Requests)

As of FME Flow 2026.1, Flow App API tokens have been deprecated. Flow App permissions will no longer be configured via token permissions; instead, they will be set by the user when creating the Flow App and secured via a Flow App Identifier. This will affect all Flow Apps (Workspace Apps, Automation Apps, AR Apps, and Gallery Apps).

For information on migrating Flow Apps from 2025.2.x or older to 2026.1, see Managing Flow App Permissions in FME Flow 2026.1 or Newer.

If a Flow App, webhook, or REST API request runs the workspace, it uses an API token instead of a user account. The token must have access to the workspace and its connections.

If You Own the Token

  1. Click the User Settings icon in the top-right corner of FME Flow, then select Manage Tokens.
  2. Under API Tokens, find the token used for the workspace and click it to edit.
  3. Under Permissions, locate Connections and click the drop-down arrow next to Show Connections.
  4. Find the connection used in the workspace. Click the drop-down under Summary and select Full Access.
  5. Click Save.

Assign access permissions to an API token.

If You Do Not Own the Token

Contact your FME Flow administrator. They can grant the token the correct permissions to access the connection.

Windows Authentication

If the database connection uses Windows authentication, FME Flow uses the account running the FME Flow Engine service, not the account of the person running the workspace. On the machine where FME Flow is installed, confirm that the Log On account for the FME Flow Engine service is a Windows account with permission to the database. This typically requires an FME Flow administrator. See the Running the FME Flow System Services Under Different Accounts (Windows) documentation for more information.

Additional Resources

Was this article helpful?

We're sorry to hear that.

Please tell us why.

As of January 14th, 2026, comments on knowledge base articles have been closed. To make sure questions don’t get missed and to enable more community support, we’ve moved discussions to the FME Community. If you have a question or a comment about this article, please create a new post or create a support ticket.