Contents

Security › Authentication & Authorization

401 Unauthorized vs 403 Forbidden

401 means "I don't know who you are"; 403 means "I know who you are, and you can't do this."

The names are confusing (401 is really about authentication), so remember the meaning:

StatusMeaningClient should
401 UnauthorizedMissing, invalid, or expired credentials. Who are you?Log in again, or refresh the token
403 ForbiddenValid credentials, but not allowed. I know you; no.Not retry. Logging in again won’t help

Example:

  • No token, or token expired → 401
  • Logged in as a regular user, calling DELETE /admin/users/7 → 403

Getting this right matters because clients act on it: a frontend that sees 401 typically redirects to login or tries a refresh token. Returning 401 for a permission problem sends users into a login loop.

A nuance: 404 instead of 403

If revealing that a resource exists is itself a leak (e.g. /users/ceo-salary-review), it’s common to return 404 to unauthorized users. GitHub does this for private repos.