Short answer
Why Am I Getting a 401 API Error?
An API returns 401 Unauthorized when credentials are missing, expired, malformed, sent in the wrong place, or issued for a different environment. Compare the request with the API authentication documentation, regenerate or refresh the credential, and test a minimal request without logging the secret.
Common causes
- The Authorization header is absent or uses the wrong scheme.
- An API key, access token, signature, or session has expired.
- Production credentials are being sent to a sandbox endpoint, or the reverse.
- A proxy or code step strips or overwrites the authentication header.
Diagnostic steps
- Confirm the endpoint environment and required authentication scheme in official documentation.
- Inspect header names and prefixes while keeping secret values redacted.
- Create or refresh a least-privilege credential and test the smallest supported endpoint.
- Store the working secret in the platform connection or secret store, not directly in logs or shared code.
Example
An endpoint expects “Authorization: Bearer TOKEN,” but the request sends the raw token without Bearer. Correcting the header format resolves the 401.
Caveats
A 401 concerns authentication; a 403 usually means the authenticated identity lacks permission. Never paste live secrets into support tickets.