A 401 Unauthorized error means the page you asked for needs a login, and the server didn't receive a valid username and password. On our hosting it almost always comes from a password-protected folder. This guide explains what the 401 Unauthorized error means and how to fix it, whether you're the visitor or the site owner.
What the 401 error looks like
- A browser pop-up titled Sign in (Chrome and Edge), Authentication Required (Firefox) or a login sheet (Safari), asking for a username and password before the page loads.
- After you cancel the pop-up or enter the wrong details: a page saying "401 Unauthorized", "Authorization Required" or
HTTP ERROR 401. - For apps and plugins: a message such as "401 Unauthorized", "Invalid credentials" or a WordPress REST API error with the status 401.
A 401 is different from a 403 Forbidden. With a 401, logging in with the right details fixes it. With a 403, logging in makes no difference because access is refused anyway.
Common causes on Instant Access Internet Services hosting
- Directory Privacy. A folder (or the whole site) has been password-protected with cPanel's Directory Privacy tool. Anyone without the username and password gets a 401.
- A wrong or forgotten password for that protected folder. Note this is its own username and password, not your cPanel or WordPress login.
- Saved, out-of-date details in the browser. Browsers remember the login for a protected folder. After a password change they may keep sending the old one.
- An app, plugin or script calling an API without a valid key, token or application password.
If you're a visitor
- Check that you're typing the username and password the site owner gave you for this folder. They are case-sensitive.
- If the browser keeps rejecting you without asking again, close every window of the browser and reopen it, or try a private/incognito window. That clears saved folder logins.
- If you don't have the details, ask the site owner. The host can't give out passwords for someone else's site.
Don't keep guessing. Repeated failed logins can make our firewall block your IP address for a while, and then the site won't load at all.
If you own the site: fix a password-protected folder
Check which folder is protected
- Log in to cPanel and go to Files > Directory Privacy.
- Click folder names to move through your folders. A lock icon shows folders that have Directory Privacy settings.
- Click Edit next to the folder to see whether Password protect this directory is ticked.
If public_html itself is protected, your whole website asks for a password. If that wasn't intended, untick Password protect this directory and click Save.
Reset a forgotten folder password
- In Directory Privacy, click Edit next to the protected folder.
- Under the create user section, enter the existing Username and type a new password twice (or use Password Generator).
- Click Save. This replaces the old password for that user.
- Close and reopen your browser, then log in with the new password.
To remove someone's access, select them under Authorized Users and click Delete User.
Still getting a 401 with the right password?
- Directory Privacy writes its rules into the folder's
.htaccessfile. If you (or a plugin) edited that file, the rules may be broken. Show hidden files in File Manager and check it, or remove and re-add the protection. - Protecting
wp-adminthis way can block parts of WordPress that calladmin-ajax.php, causing 401 errors for visitors. Protect a different folder, or use WordPress's own security options instead. - Look in Metrics > Errors for lines mentioning "authentication failure" or "user not found". They show which folder and username were tried.
401 errors from WordPress plugins and apps
If the 401 appears in an app, a connected service or a plugin's settings page, the login details that app uses are wrong or expired. Reconnect the service, generate a new API key or WordPress application password (in Users > Profile), and update it in the app. Security plugins can also block the WordPress REST API for logged-out users, which some themes and apps need; check the plugin's settings.
Common questions
Is 401 the same as a wrong cPanel or webmail password?
No. cPanel, webmail and WordPress show their own "login failed" messages. A 401 page comes from a protected web folder or an API. If you can't get into cPanel, see the login guide below.
Suddenly the site won't load at all after failed logins
Your IP address has probably been blocked by our firewall after too many failed attempts. Open a ticket with your IP address from whatismyipaddress.com and we'll unblock it.
When to open a ticket
Open a ticket if you've checked Directory Privacy and the error continues. Include the full page address, the folder you expect to be protected (or not), the exact error, when it happened and your IP address.
Related guides
- How to Password-Protect a Folder with cPanel Directory Privacy
- How to Show Hidden Files (.htaccess) in cPanel File Manager
- 403 Forbidden Error: What It Means and How to Fix It
- How to Log In to cPanel Directly and Reset a Forgotten Password
- ERR_CONNECTION_TIMED_OUT and ERR_CONNECTION_REFUSED: How to Fix Them
Still stuck? Open a support ticket and the Instant Access Internet Services team will help.
