HTTP 401 – Unauthorized
The client must authenticate itself to get the requested response.
Common use case
Returned when a request is missing credentials or presents an invalid/expired token, prompting the client to log in or refresh its session.
Example
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer
{"error":"Invalid or expired token"}History
Part of HTTP/1.0 (RFC 1945, 1996).
Did you know?
Despite the name, 401 really means "unauthenticated" - it is frequently confused with 403, which means the client is known but not allowed.