HTTP

401 Unauthorized

You aren't authenticated — the server doesn't know who you are.

What it looks like

HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer error="invalid_token", error_description="The access token expired"

What does "401 Unauthorized" mean?

Returned when a request needs authentication and none was accepted. Despite the name it means unauthenticated — the server does not know who you are. (Known but not allowed is 403.) APIs usually say why in the WWW-Authenticate header or the body.

What causes "401 Unauthorized"?

  • Missing, expired, or wrong auth token / API key.
  • The Authorization header isn't being sent.
  • Session/cookie expired.

How do I confirm the cause?

  1. In the Network tab, check the request actually carries the Authorization header or session cookie.
  2. Decode the token (a JWT decoder shows its exp claim) to see whether it has expired or is for the wrong audience.
  3. If it fails only from the browser, check whether a CORS preflight or a proxy is dropping the Authorization header.
  4. Check the header format: many APIs expect exactly Authorization: Bearer followed by the token, and a missing Bearer prefix returns 401.

How do I fix "401 Unauthorized"?

  • Send a valid token in the Authorization header.
  • Re-login / refresh the token.
  • Confirm the header survives any proxy or CORS preflight.

How do I stop it happening again?

  • Refresh tokens before they expire, and retry once with a fresh token on a 401.
  • Keep API keys in environment variables and rotate them deliberately, so an expired key is never a surprise.
Got a different error? Paste it into the Explain This Error tool → Identifies the family and the fix — runs locally, nothing uploaded.

Related errors