What is a WWW-Authenticate header?
Indicates the authentication scheme(s) that must be used to access the resource, sent with a 401 response.
WWW-Authenticate accompanies a 401 Unauthorized response to tell the client exactly which authentication scheme a website expects - Basic, Bearer, Digest, and so on - so it knows how to actually retry the request correctly instead of just failing. A monitor testing authenticated endpoints benefits from checking this header lines up with what the API documentation promises, since a mismatch usually means the auth middleware and the docs have drifted apart.
Common use case
A browser hitting a Basic-auth-protected page for the first time reads WWW-Authenticate: Basic and pops up its native username/password prompt in response.
Example
WWW-Authenticate: Bearer realm="api", error="invalid_token"History
Part of the original HTTP/1.0 specification, RFC 1945 (1996).
Did you know?
OAuth 2.0's Bearer scheme extended this header with structured error parameters like invalid_token and insufficient_scope, letting a client understand exactly why authentication failed rather than just that it did.