POST /api/v2/webmessaging/sessions/{sessionId}/close returning 403 for service account

Trying to close web messaging sessions programmatically from our backend to clean up OTel traces. Calling the endpoint to close a session with a service account token. Getting a 403 Forbidden.

The account has webmessaging:session:write scope. Works fine for creating sessions. The session ID is valid and active.

Is there a specific permission needed for closing? Or is this operation restricted to the guest token only?

2 Likes

webmessaging:session:write isn’t enough. You need webmessaging:session:admin.

The close operation requires administrative rights over the session lifecycle. Service accounts usually miss this unless explicitly granted.

Check the client scopes in your OAuth client config. Add webmessaging:session:admin and regenerate the token.

# Note: There is no dedicated REST endpoint to close a web messaging session.
# Session closure is typically handled via the SDK or by letting the session timeout.
# If you are trying to terminate the interaction programmatically, ensure your
# service account has the appropriate permissions to manage the session state
# through the supported methods.

If that still 403s, verify the service account user role has the “Web Messaging Administrator” feature enabled. Sometimes the scope is there but the user profile blocks the action.

1 Like