DevToolPal
EN
4xx Client errors

401 Unauthorized

What it means

The request lacks valid authentication credentials. Despite the name it means unauthenticated: log in or send a valid token.

Common causes

  • Missing Authorization header
  • Expired or revoked token
  • Wrong username, password or API key

How to fix it

As a client or visitor

Send credentials in the format the WWW-Authenticate header asks for, refresh expired tokens, and check for typos or the wrong environment's key.

As the site or API owner

Always include a WWW-Authenticate header with 401. Use 403 when the user is authenticated but not allowed.

Example response

HTTP/1.1
HTTP/1.1 401 Unauthorized
Date: Tue, 07 Oct 2025 09:30:00 GMT
Server: nginx
WWW-Authenticate: Bearer realm="api", error="invalid_token"
Content-Type: application/problem+json

{
  "type": "about:blank",
  "title": "Unauthorized",
  "status": 401,
  "detail": "The access token expired."
}

Specification

RFC 9110 §15.5.2

FAQ

› 401 vs 403?

401: we do not know who you are, authenticate. 403: we know who you are, and you may not do this.

› Why do I get 401 right after logging in?

Usually the token is not attached to requests (CORS without credentials, wrong header name) or the clock skew makes it look expired.