401 Unauthorized Error: What It Means and How to Fix It

A 401 Unauthorized error means the page you asked for needs a login, and the server didn't receive a valid username and password. On our hosting it almost always comes from a password-protected folder. This guide explains what the 401 Unauthorized error means and how to fix it, whether you're the visitor or the site owner.

What the 401 error looks like

  • A browser pop-up titled Sign in (Chrome and Edge), Authentication Required (Firefox) or a login sheet (Safari), asking for a username and password before the page loads.
  • After you cancel the pop-up or enter the wrong details: a page saying "401 Unauthorized", "Authorization Required" or HTTP ERROR 401.
  • For apps and plugins: a message such as "401 Unauthorized", "Invalid credentials" or a WordPress REST API error with the status 401.

A 401 is different from a 403 Forbidden. With a 401, logging in with the right details fixes it. With a 403, logging in makes no difference because access is refused anyway.

Common causes on Instant Access Internet Services hosting

  • Directory Privacy. A folder (or the whole site) has been password-protected with cPanel's Directory Privacy tool. Anyone without the username and password gets a 401.
  • A wrong or forgotten password for that protected folder. Note this is its own username and password, not your cPanel or WordPress login.
  • Saved, out-of-date details in the browser. Browsers remember the login for a protected folder. After a password change they may keep sending the old one.
  • An app, plugin or script calling an API without a valid key, token or application password.

If you're a visitor

  1. Check that you're typing the username and password the site owner gave you for this folder. They are case-sensitive.
  2. If the browser keeps rejecting you without asking again, close every window of the browser and reopen it, or try a private/incognito window. That clears saved folder logins.
  3. If you don't have the details, ask the site owner. The host can't give out passwords for someone else's site.

Don't keep guessing. Repeated failed logins can make our firewall block your IP address for a while, and then the site won't load at all.

If you own the site: fix a password-protected folder

Check which folder is protected

  1. Log in to cPanel and go to Files > Directory Privacy.
  2. Click folder names to move through your folders. A lock icon shows folders that have Directory Privacy settings.
  3. Click Edit next to the folder to see whether Password protect this directory is ticked.

If public_html itself is protected, your whole website asks for a password. If that wasn't intended, untick Password protect this directory and click Save.

Reset a forgotten folder password

  1. In Directory Privacy, click Edit next to the protected folder.
  2. Under the create user section, enter the existing Username and type a new password twice (or use Password Generator).
  3. Click Save. This replaces the old password for that user.
  4. Close and reopen your browser, then log in with the new password.

To remove someone's access, select them under Authorized Users and click Delete User.

Still getting a 401 with the right password?

  • Directory Privacy writes its rules into the folder's .htaccess file. If you (or a plugin) edited that file, the rules may be broken. Show hidden files in File Manager and check it, or remove and re-add the protection.
  • Protecting wp-admin this way can block parts of WordPress that call admin-ajax.php, causing 401 errors for visitors. Protect a different folder, or use WordPress's own security options instead.
  • Look in Metrics > Errors for lines mentioning "authentication failure" or "user not found". They show which folder and username were tried.

401 errors from WordPress plugins and apps

If the 401 appears in an app, a connected service or a plugin's settings page, the login details that app uses are wrong or expired. Reconnect the service, generate a new API key or WordPress application password (in Users > Profile), and update it in the app. Security plugins can also block the WordPress REST API for logged-out users, which some themes and apps need; check the plugin's settings.

Common questions

Is 401 the same as a wrong cPanel or webmail password?

No. cPanel, webmail and WordPress show their own "login failed" messages. A 401 page comes from a protected web folder or an API. If you can't get into cPanel, see the login guide below.

Suddenly the site won't load at all after failed logins

Your IP address has probably been blocked by our firewall after too many failed attempts. Open a ticket with your IP address from whatismyipaddress.com and we'll unblock it.

When to open a ticket

Open a ticket if you've checked Directory Privacy and the error continues. Include the full page address, the folder you expect to be protected (or not), the exact error, when it happened and your IP address.

Related guides

Still stuck? Open a support ticket and the Instant Access Internet Services team will help.

Ultrafast LiteSpeed hosting from InstantAccess.net: free SSL, free backups, cPanel included, no contracts. Check out our $10/month hosting.
  • 401 unauthorized, http error 401, 401 unauthorized error fix, 401 authorization required, password protected directory 401, wordpress rest api 401
  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

429 Too Many Requests: What It Means and How to Fix It

A 429 Too Many Requests error means something decided that one visitor, program or website sent...

500 Internal Server Error: What It Means and How to Fix It

A 500 Internal Server Error means the web server hit a problem it couldn't recover from while...

400 Bad Request Error: What It Means and How to Fix It

A 400 Bad Request error means the server received a request it couldn't understand, so it refused...

403 Forbidden Error: What It Means and How to Fix It

A 403 Forbidden error means the server understood the request but refused to show the page....

404 Not Found Error: What It Means and How to Fix It

A 404 Not Found error means the server is working, but there's nothing at the address that was...