Security › Authentication & Authorization
401 Unauthorized vs 403 Forbidden
401 means "I don't know who you are"; 403 means "I know who you are, and you can't do this."
The names are confusing (401 is really about authentication), so remember the meaning:
| Status | Meaning | Client should |
|---|---|---|
| 401 Unauthorized | Missing, invalid, or expired credentials. Who are you? | Log in again, or refresh the token |
| 403 Forbidden | Valid credentials, but not allowed. I know you; no. | Not retry. Logging in again won’t help |
Example:
- No token, or token expired → 401
- Logged in as a regular user, calling
DELETE /admin/users/7→ 403
Getting this right matters because clients act on it: a frontend that sees 401 typically redirects to login or tries a refresh token. Returning 401 for a permission problem sends users into a login loop.
A nuance: 404 instead of 403
If revealing that a resource exists is itself a leak (e.g. /users/ceo-salary-review),
it’s common to return 404 to unauthorized users. GitHub does this for private repos.