401 vs 403: Unauthorized vs Forbidden

Both mean “you can’t have this”, but for different reasons. 401 says the server doesn’t know who you are; 403 says it knows exactly who you are, and the answer is still no.

401

HTTP 401 Unauthorized

The request has no valid authentication credentials — you need to log in or send a valid token.

Causes & fixes →
403

HTTP 403 Forbidden

The server understood the request but refuses to authorize it — you (or the server process) are not allowed to access this resource.

Causes & fixes →
401403
Question answeredWho are you? (authentication)Are you allowed? (authorization)
Typical causeMissing, expired or invalid token / sessionValid user without the required role, scope or file permission
Will logging in help?Yes — send valid credentialsUsually no — you need more permissions
Required headerWWW-Authenticate should be presentNone
Client actionRefresh token or redirect to loginShow “no access”, request permission
Web server exampleBasic auth promptFile permissions, deny rules, missing index

Rule of thumb

If re-authenticating could fix it, it’s a 401. If the user is known but not allowed, it’s a 403.