Independent technical referenceOfficial site
  • Software and systems
  • HTTP service

401

HTTP 401 Unauthorized: valid authentication credentials are missing

Verified with sources2 sourcesReviewed Aug 22, 2026
Technician coming? See what they must show you

Risk level

Low

Usually safe to check without specialist tools.

Urgency

Medium

Quick answer

HTTP 401 means the request was not applied because it lacks valid authentication credentials for the target resource. The server must send at least one applicable challenge in WWW-Authenticate.

Safety first

Stop and check this first

  • Never paste an Authorization header API key session cookie refresh token or password into a public diagnostic. Share only the redacted challenge request ID and timestamp.

Safe checks you can perform

  • Inspect the WWW-Authenticate challenge
  • Confirm which credential the target expects
  • Retry once with new or replaced authorization

Leave these tasks to a qualified professional

  • Do not attempt this professional task: Trace the challenge and credential validation path

What a technician must be able to justify

A technician is coming

These are the steps they must carry out and show you. Tick them as they work: if steps are skipped, do not accept a part swap.

These are not instructions for opening or handling the equipment yourself. They are the checks that should support a technical conclusion.

  1. Trace the challenge and credential validation path

    What they doThe identity or API owner should correlate the request identifier with authentication logs and verify scheme realm token lifetime issuer audience and clock handling without recording the credential itself.

Before accepting a part or repair

Nothing has been shown yet. Do not accept a part swap based on the code alone.

Checks and evidence, step by step

Follow the documented order. An error code identifies the affected system, but it does not prove by itself which part has failed.

  1. 1

    Inspect the WWW-Authenticate challenge

    Tools required

    Procedure

    Record the authentication scheme and realm advertised in WWW-Authenticate without copying credentials tokens cookies or private parameters. A 401 response must contain at least one applicable challenge.

    Treat Authorization headers tokens cookies and passwords as secrets and never place them in screenshots or public logs.

    Evidence: RFC 9110 section 15.5.2 - 401 Unauthorized · RFC 9110 section 11.6.1 - WWW-Authenticate

  2. 2

    Confirm which credential the target expects

    Tools required

    Procedure

    Compare the challenge and target realm with the service documentation then verify that the client sends the correct credential type to the correct origin.

    Do not send credentials to a different host or downgrade to a weaker scheme simply to remove 401.

    Evidence: RFC 9110 section 11.6.1 - WWW-Authenticate

  3. 3

    Retry once with new or replaced authorization

    No special tools

    Procedure

    After correcting or renewing the credential repeat a safe request once. If the same challenge and 401 return preserve the response details for the service owner.

    Repeated failed authentication can trigger lockouts and does not prove that the account needs more permissions.

    Evidence: RFC 9110 section 15.5.2 - 401 Unauthorized

Where this code applies

A code is meaningful only inside the right product and version context.

Primary scope

System
Software and systems
Brand
HTTP
Product type
HTTP service

Known code variants

  • 401 Nicht autorisiert
  • 401 No autorizado
  • 401 Non autorizzato
  • 401 Unauthorized
  • code erreur 401
  • événement Fronius 401
  • événement SMA 401
  • evento Fronius 401
  • evento SMA 401
  • Fronius Ereignis 401
  • Fronius event 401
  • Fronius inverter 401
  • Fronius Symo / Eco 401
  • Fronius Wechselrichter 401
  • HTTP 401
  • HTTP status 401
  • inversor Fronius 401
  • inversor SMA 401
  • inverter Fronius 401
  • inverter SMA 401
  • onduleur Fronius 401
  • onduleur SMA 401
  • SMA Ereignis 401
  • SMA event 401
  • SMA inverter 401
  • SMA Wechselrichter 401
  • status code 401
  • Sunny Tripower X 401

What it means

If credentials were already sent the origin refused them. A 401 is an authentication challenge and is distinct from 403 where valid credentials can still be insufficient.

Warnings and stop conditions

  • Higheditorial warning

    Never paste an Authorization header API key session cookie refresh token or password into a public diagnostic. Share only the redacted challenge request ID and timestamp.

    Evidence: RFC 9110 section 11.6.1 - WWW-Authenticate

Symptoms and causes

Probable causes · in order

  • The request lacks valid credentials for the resourceConfirmed

    RFC 9110 defines 401 when a request has not been applied because it lacks valid authentication credentials for the target resource.

    Evidence: RFC 9110 section 15.5.2 - 401 Unauthorized

  • Supplied credentials were refusedPossible

    When the request already contained credentials a 401 response means authorization was refused for those credentials.

    Evidence: RFC 9110 section 15.5.2 - 401 Unauthorized

Virtual technician

Does 401 still appear after these checks?

Answer a few questions to narrow down the likely cause and the safest next action. Guidance only - it never replaces a professional.

Sources and technical references

  1. 1

    RFC 9110 section 15.5.2 - 401 Unauthorized

    Internet Engineering Task Force · 2022 · official_doc

  2. 2

    RFC 9110 section 11.6.1 - WWW-Authenticate

    Internet Engineering Task Force · 2022 · official_doc

Sources: RFC 9110 section 15.5.2 - 401 Unauthorized · RFC 9110 section 11.6.1 - WWW-Authenticatereviewed 2026-08-22 · verified

Was this entry useful?