401 Unauthorized
The request lacks valid authentication credentials for the target resource.
| Class | Client error (4xx) |
|---|---|
| Defined in | RFC9110, Section 15.5.2 |
| Cacheable by default | No, unless explicit freshness headers allow it |
Common causes
- No credentials were sent, or the token or password is wrong or expired.
- The Authorization header uses the wrong scheme.
What to do
Send valid credentials. The response must include a WWW-Authenticate header telling the client how to authenticate. Note that 401 means unauthenticated, while 403 means authenticated but not allowed.
Related codes
- 403 Forbidden: The server understood the request but refuses to authorize it.
- 407 Proxy Authentication Required: Like 401, but the client must authenticate with the proxy first.
- 400 Bad Request: The server cannot process the request because it looks malformed.