405 🌐 HTTP

HTTP 405 Method Not Allowed

The URL exists, but it doesn’t accept the HTTP method you used (e.g. POST to a GET-only route).

Seen on: Nginx Node.js PHP

Meaning

The server recognizes the resource but not the verb. A proper 405 response includes an Allow header listing permitted methods, such as Allow: GET, HEAD.

It often appears when a form posts to the wrong URL, when a static file server receives a POST, or when CORS preflight OPTIONS requests aren’t handled.

Common causes

  • Route defined for GET but request uses POST/PUT/DELETE (or vice versa)
  • Posting to a static file — Nginx returns 405 for POST to static content
  • CORS preflight OPTIONS not handled by the server
  • Redirect (301/302) turned a POST into a GET, hitting a POST-only route
  • Trailing-slash redirect on frameworks like Django/Express changes the request
  • WebDAV or IIS handler mappings disabling PUT/DELETE

⚡ Quick fix

  1. Check the Allow response header to see accepted methods
  2. Match the client method to the route definition
  3. Handle OPTIONS for CORS preflight (most CORS middleware does this)
  4. Use the canonical URL (with/without trailing slash) to avoid redirects that change the method

Detailed fix by platform

Nginx

  1. POST to static files returns 405. Proxy the path to your app instead of serving it statically.
  2. Example:
    nginx
    location /api/ {
        proxy_pass http://127.0.0.1:3000;
    }

Node.js

  1. Express: register the method you call.
    javascript
    app.post('/api/users', createUser);   // a POST to a route defined only with app.get → 404/405
    app.options('*', cors());             // preflight

PHP

  1. In Laravel, php artisan route:list shows allowed methods; HTML forms need @method('PUT') for PUT/DELETE.

Code examples

Check allowed methods

bash
curl -i -X OPTIONS https://api.example.com/users
curl -i -X POST https://api.example.com/users   # look for the Allow: header

How to diagnose

  1. Method — Which method did the client actually send (DevTools / logs)?
  2. Allow header — Which methods does the server allow for that URL?
  3. Redirects — Did a redirect change POST into GET?
  4. Preflight — Is the failing request an OPTIONS preflight?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.