HTTP 401 — Unauthorized
HTTP 401
Unauthorized
You need to authenticate, and either you did not or your credentials were rejected.
What 401 actually means
Despite the name, 401 means unauthenticated, not unauthorised. The server does not know who you are, or does not accept the credentials you offered. The response is required to carry a `WWW-Authenticate` header naming the scheme it expects — Basic, Bearer, Negotiate — which is what makes a browser pop up a username-and-password box. The distinction from 403 is the useful part: 401 says "log in", 403 says "logging in will not help".
Common causes
- No `Authorization` header was sent
- An API token or session has expired
- Wrong username or password
- A bearer token was signed with the wrong key, or its issuer/audience claims do not match
- The clock on the client is skewed enough to make a token look not-yet-valid or expired
If you're just trying to view the page
- Sign in again — the most common cause is simply an expired session
- Check the username and password, including caps lock and leading or trailing spaces
- Clear that site's cookies to drop a stale session, then log in fresh
- If your organisation uses single sign-on, sign out of the identity provider entirely and start again
If it's your site
- Always send a `WWW-Authenticate` header; a 401 without one is technically invalid and breaks clients that try to respond to the challenge
- Distinguish expired-token from invalid-token in the error body so clients know whether to refresh or re-prompt
- Check clock skew between token issuer and verifier — a minute of drift will invalidate JWTs
- Verify the token audience, issuer and signing key match what you expect; misconfigured `aud` claims are a frequent cause
- Confirm proxies are forwarding the `Authorization` header — some strip it by default on redirects and cross-origin hops
Reference
- Status code
- 401
- Reason phrase
- Unauthorized
- Category
- 4xx — Client Error
- Defined in
- RFC 9110 §15.5.2
Common questions
- What does HTTP 401 mean?
- You need to authenticate, and either you did not or your credentials were rejected. Despite the name, 401 means unauthenticated, not unauthorised. The server does not know who you are, or does not accept the credentials you offered.
- How do I fix a 401 error?
- Sign in again — the most common cause is simply an expired session
- Is 401 a client error or a server error?
- 401 is in the 4xx range, which means client error. The request itself was the problem, so retrying it unchanged will usually return the same code.
Related pages
- 404 Not Found The server is reachable and working, but there is nothing at the address you ask
- 403 Forbidden The server understood the request and is refusing to allow it, and logging in wi
- 429 Too Many Requests You have sent more requests than the service allows in a given period.
- 400 Bad Request The server could not understand the request because something about it is malfor
- 413 Content Too Large The request body is bigger than the server is willing to accept.
- 422 Unprocessable Content The request is well-formed and understood, but the data in it fails the rules.
- 405 Method Not Allowed The URL exists, but it does not accept the HTTP method you used.
- 409 Conflict The request cannot be completed because it clashes with the current state of the
- 415 Unsupported Media Type The server will not accept the format of the body you sent.
- 408 Request Timeout The server gave up waiting for the client to finish sending its request.
- 410 Gone The resource was deliberately removed and is not coming back, and there is no fo
- 451 Unavailable For Legal Reasons The content is blocked because of a legal demand — a court order, takedown notic