← All status codes4xx – Client Error

HTTP 401 – Unauthorized

The client must authenticate itself to get the requested response.

Common use case

Returned when a request is missing credentials or presents an invalid/expired token, prompting the client to log in or refresh its session.

Example

HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer

{"error":"Invalid or expired token"}

History

Part of HTTP/1.0 (RFC 1945, 1996).

Did you know?

Despite the name, 401 really means "unauthenticated" - it is frequently confused with 403, which means the client is known but not allowed.