401 vs 403: Unauthorized vs Forbidden
Both mean “you can’t have this”, but for different reasons. 401 says the server doesn’t know who you are; 403 says it knows exactly who you are, and the answer is still no.
401
HTTP 401 Unauthorized
The request has no valid authentication credentials — you need to log in or send a valid token.
Causes & fixes →
403
HTTP 403 Forbidden
The server understood the request but refuses to authorize it — you (or the server process) are not allowed to access this resource.
Causes & fixes →| 401 | 403 | |
|---|---|---|
| Question answered | Who are you? (authentication) | Are you allowed? (authorization) |
| Typical cause | Missing, expired or invalid token / session | Valid user without the required role, scope or file permission |
| Will logging in help? | Yes — send valid credentials | Usually no — you need more permissions |
| Required header | WWW-Authenticate should be present | None |
| Client action | Refresh token or redirect to login | Show “no access”, request permission |
| Web server example | Basic auth prompt | File permissions, deny rules, missing index |
Rule of thumb
If re-authenticating could fix it, it’s a 401. If the user is known but not allowed, it’s a 403.