Errors / HTTP errors
401 Unauthorized
The page needs you to be signed in, or a valid key, and the request did not have one.
The page, or the data behind it, does not load; for signed-in visitors, often a sudden logout.
Seeing it on someone else’s site?
- Sign in again: the session has probably expired.
- Unlike 403, a 401 means proving who you are would let you in.
Why it happens, if it is your site
- No credentials sent, or an expired session or token.
- A public page calling an API that requires login, for a visitor who is not signed in.
- An API key missing in production (an environment variable not set).
- Some bot-protection probes answer 401 on purpose, as part of their check; those are normal.
How to fix it
- Check the request carries the header or cookie the API expects.
- On public pages, only call authenticated APIs once someone is signed in.
- Renew or set the key in the environment where it fails.
Whose problem it is
Either the site's own code or a third party's, depending on where it comes from.
Does your site have it?
Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.
Often seen with
- 403 ForbiddenThe server understood the request and refuses to let you see this.