HTTP 4xx
401 Unauthorized
Authentication is required and has failed or not been provided.
What causes it
- A missing, expired, or invalid credential or token.
How to fix it
Provide valid credentials. Check that tokens have not expired and that the Authorization header is being sent.
Example response
A typical raw HTTP response a client receives for a 401, with the headers this code is defined around.
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer realm="api"
Content-Type: text/html; charset=utf-8Related codes
400Common
Bad RequestThe server could not understand the request, usually because it was malformed.403Common
ForbiddenThe server understood the request but refuses to authorize it. Unlike 401, authenticating will not help.404Common
Not FoundThe server could not find the requested resource. The URL may be wrong or the resource may have been removed.405
Method Not AllowedThe HTTP method is not supported for this resource, for example a POST to a read-only endpoint.408
Request TimeoutThe server timed out waiting for the client to finish the request.410
GoneThe resource was intentionally removed and will not come back. A stronger, permanent signal than 404.Know before your visitors do.
Sentinel checks your site around the clock from multiple regions and alerts you the moment it starts returning a 4xx error, so you can fix it before it costs you.