401 vs 403: What's the Difference?
A 401 response means the request lacks valid authentication credentials; a 403 response means the server understood the request but refuses access. In short, 401 asks you to authenticate, while 403 says the authenticated request is not allowed.
Compare the two status codes
| Code | Meaning | Typical next step |
|---|---|---|
| 401 Unauthorized | Credentials are missing, invalid, or expired. | Sign in or send valid credentials; the server can include a WWW-Authenticate challenge. |
| 403 Forbidden | The server refuses this request even though it can understand it. | Check permissions, account role, resource policy, or IP restrictions. |
How to tell which one you have
Check the response body and authentication headers, then verify whether the request is signed in as the intended user. A 401 commonly includes a WWW-Authenticate header. A 403 commonly points to an authorization policy or permission decision, and repeating the same request with the same credentials usually will not help.
Worked example
Imagine a protected billing API. If the request has no access token, the API can return 401 and ask the client to authenticate. If the token is valid but belongs to a read-only user who requests an admin action, the API can return 403. That difference tells the client whether to sign in or request permission.
FAQs
- Is 401 the same as 403?
- No. A 401 indicates authentication is missing or invalid; a 403 indicates the server refuses the authenticated request.
- Should I retry after a 403?
- Retry only after a relevant permission or policy changes. Repeating the same request with the same access usually returns the same refusal.
- Does a 401 always mean the user needs to log in?
- Usually it means valid credentials are required, but an API token may need to be renewed or sent using the authentication scheme the server expects.
Related tools
Inspect a URL's response and redirects with the HTTP Status Checker.