4xx

401 Unauthorized

The request requires authentication and valid credentials were not provided.

What is HTTP 401?

This status code indicates that the request lacks valid authentication credentials for the target resource. The response must include a WWW-Authenticate header indicating the authentication scheme the server expects. Despite its name, this code actually means 'unauthenticated' rather than 'unauthorized' - the server does not know who the client is. The client should retry the request with proper credentials such as a token, API key, or username and password.

Defined in RFC 9110

Common Causes

  • No authentication token, API key, or session cookie was included in the request
  • The provided token or credentials have expired and need to be refreshed
  • An incorrect or malformed Authorization header was sent
  • The session was invalidated due to password change or logout on another device

How to Fix

  • Include valid credentials in the request, typically via an Authorization header or session cookie
  • If the token expired, refresh it using your authentication flow and retry the request
  • Verify the authentication scheme matches what the server expects in the WWW-Authenticate header
  • Log in again to obtain fresh credentials if the session was invalidated