I’ve worked through this exact scenario multiple times. Here’s the comprehensive solution addressing all three critical areas:
1. REST API ACL Configuration
The 403 error stems from insufficient type-level permissions. Navigate to Site > Utilities > Access Control and verify your REST API user or role has explicit Create grant on the Nonconformance object type. Context-level permissions aren’t sufficient - you need type-level grants:
Object Type: wt.quality.Nonconformance
Principal: [Your REST API User/Role]
Permission: Create (Grant)
Critically, also check the parent Quality Management context ACL to ensure no Deny rules are cascading down.
2. Custom Attribute Permissions
This is the most common culprit. Open Type and Attribute Management, select your Nonconformance type, and for EACH custom attribute:
- Security tab: Verify Modify permission is granted (not inherited with restrictions)
- Advanced tab: Ensure ‘Include in REST API’ is checked
- Validation tab: Confirm no cross-attribute dependencies require UI-only fields
Required attributes need explicit Modify grants. If any required attribute has conditional visibility or permissions based on lifecycle state, the REST creation will fail at initial state.
3. Nonconformance Object Model Specifics
The nonconformance object model has unique requirements:
// Your payload needs these minimum fields:
{
"ContainerReference": "/Windchill/servlet/odata/ProdMgmt/Containers('OR:wt.pdmlink.PDMLinkProduct:12345')",
"Number": "NC-2025-001",
"Description": "Supplier defect",
"Severity": "High",
"LifeCycleState": "INWORK"
}
Key points:
- ContainerReference must point to valid Quality container OID
- LifeCycleState must match initial state from lifecycle template
- If your model has custom IBA attributes, include them with proper type casting
Verification Steps:
- Test with minimal payload (only required OOTB fields) to isolate custom attribute issues
- Enable verbose REST logging:
log4j.logger.wt.rest=DEBUG in log4j.properties
- Check MethodServer.log for actual permission denial details
- Verify REST user can create other quality objects (like Quality Events) to rule out general quality context issues
Common Gotcha in 11.1:
If you have workflow processes attached to nonconformance creation, ensure the REST user has Execute permission on the workflow template. Some organizations restrict workflow initiation to UI users, causing REST creation failures.
After implementing these changes, restart method server and test with a minimal payload first, then gradually add custom attributes to identify any problematic fields. The 403 should resolve once all three areas are properly configured.
This draft is based on general Windchill knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.