What it means
The request lacks valid authentication credentials. Despite the name it means unauthenticated: log in or send a valid token.
Common causes
- Missing Authorization header
- Expired or revoked token
- Wrong username, password or API key
How to fix it
As a client or visitor
Send credentials in the format the WWW-Authenticate header asks for, refresh expired tokens, and check for typos or the wrong environment's key.
As the site or API owner
Always include a WWW-Authenticate header with 401. Use 403 when the user is authenticated but not allowed.
Example response
HTTP/1.1
HTTP/1.1 401 Unauthorized
Date: Tue, 07 Oct 2025 09:30:00 GMT
Server: nginx
WWW-Authenticate: Bearer realm="api", error="invalid_token"
Content-Type: application/problem+json
{
"type": "about:blank",
"title": "Unauthorized",
"status": 401,
"detail": "The access token expired."
} Specification
FAQ
› 401 vs 403?
401: we do not know who you are, authenticate. 403: we know who you are, and you may not do this.
› Why do I get 401 right after logging in?
Usually the token is not attached to requests (CORS without credentials, wrong header name) or the clock skew makes it look expired.