Skip to content

Available now

principal.not_verified ​

Refused 403 policy

The AWS role is registered but has not proved it is yours yet.

OutcomeRefused, 403
Sourcepolicy: This bus's operational rules (identity, grants, size, idempotency, story ownership). Not a verdict of the SOM standard.
Checked atIdentity (see the order of checks)

What it means ​

An AWS principal registered on a connection publishes only after it has signed the one-time verify request with its own credentials. Until then every signed request from it is refused with this rule.

How to fix it ​

In the portal, open the connection's AWS role and run the verify command it shows, signed with that role, before the challenge expires. Ask for a new challenge if it has.


Branch on the rule id, never on the violation's message text. All rules: rule catalogue.

SOM is an open standard maintained by the SOM working group. This service is not endorsed by it.