Error Reference › HTTP
HTTP
401 Unauthorized
You aren't authenticated — the server doesn't know who you are.
What it looks like
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer error="invalid_token", error_description="The access token expired"
What does "401 Unauthorized" mean?
Returned when a request needs authentication and none was accepted. Despite the name it means unauthenticated — the server does not know who you are. (Known but not allowed is 403.) APIs usually say why in the WWW-Authenticate header or the body.
What causes "401 Unauthorized"?
- Missing, expired, or wrong auth token / API key.
- The Authorization header isn't being sent.
- Session/cookie expired.
How do I confirm the cause?
- In the Network tab, check the request actually carries the Authorization header or session cookie.
- Decode the token (a JWT decoder shows its exp claim) to see whether it has expired or is for the wrong audience.
- If it fails only from the browser, check whether a CORS preflight or a proxy is dropping the Authorization header.
- Check the header format: many APIs expect exactly Authorization: Bearer followed by the token, and a missing Bearer prefix returns 401.
How do I fix "401 Unauthorized"?
- Send a valid token in the Authorization header.
- Re-login / refresh the token.
- Confirm the header survives any proxy or CORS preflight.
How do I stop it happening again?
- Refresh tokens before they expire, and retry once with a fresh token on a 401.
- Keep API keys in environment variables and rotate them deliberately, so an expired key is never a surprise.