Skip to content

Errors / HTTP errors

401 Unauthorized

The page needs you to be signed in, or a valid key, and the request did not have one.

The page, or the data behind it, does not load; for signed-in visitors, often a sudden logout.

Seeing it on someone else’s site?

  • Sign in again: the session has probably expired.
  • Unlike 403, a 401 means proving who you are would let you in.

Why it happens, if it is your site

  • No credentials sent, or an expired session or token.
  • A public page calling an API that requires login, for a visitor who is not signed in.
  • An API key missing in production (an environment variable not set).
  • Some bot-protection probes answer 401 on purpose, as part of their check; those are normal.

How to fix it

  1. Check the request carries the header or cookie the API expects.
  2. On public pages, only call authenticated APIs once someone is signed in.
  3. Renew or set the key in the environment where it fails.

Whose problem it is

Either the site's own code or a third party's, depending on where it comes from.

Does your site have it?

Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.

Check only sites you run or have permission to check.

Often seen with

  • 403 ForbiddenThe server understood the request and refuses to let you see this.