401 Unauthorized Error: Why Your Site Is Asking for a Password

Visitors see "401 Unauthorized" or a browser pop-up asking for a username and password — the server wants proof of who you are before it will show the page, and the proof is missing or wrong.

Common signs of this issue

Safe checks you can do yourself

None of these require sharing passwords with anyone.

What this usually means

A 401 means "I do not know who you are." The server is not refusing you outright; it is asking for credentials and either got none or got ones it did not accept. That is different from a 403 Forbidden error, which means "I know what you are asking for and you are not allowed it," regardless of login. The practical difference: a 401 is usually fixed by supplying the right credentials or removing a password gate, while a 403 is usually fixed by changing permissions or firewall rules.

On small business sites, the most common cause is a password gate that was meant to be temporary. A developer protected the site while building it, the host protected a staging copy, or someone added a folder password in cPanel, and the protection was never removed when the site went live. Visitors then hit a browser pop-up they cannot answer. The second big group is login-page hardening: a security plugin or host feature adding a second password prompt in front of wp-login.php. That is a legitimate defense, but it causes confusion when nobody wrote down the extra credentials.

The quieter kind of 401 happens behind the scenes. The WordPress editor, mobile apps, backup services, and tools like Zapier talk to your site through its REST API, and they must prove who they are on every request. If an Application Password was revoked, a security plugin blocks REST access for non-logged-in requests, or the server strips the login header before WordPress sees it, those tools get a 401 while the site looks fine in a browser. If you cannot log in at all, start with WordPress admin login not working instead.

What not to do

When to get help

Bring in help when you cannot tell where the password gate lives, when it came from a site launch you did not handle yourself, or when a 401 is breaking the editor, a store integration, or backups. Password prompts can come from the server configuration, the host panel, Cloudflare Access, or a plugin, and removing the wrong layer can either do nothing or strip away protection you need. Someone who can see the server config and the site together finds the real gate quickly and removes only what should go.

Glenn, who runs WebsiteSelfHelp, fixes unexpected password prompts and 401 errors for small business websites, from leftover staging protection to broken API connections. Describe where the prompt or error shows up, and you will get an honest read on the cause and what it will take to clear it — no passwords needed to get started.

Not sure what to do next?

Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.

Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.

Frequently asked questions

What does 401 Unauthorized mean?

It means the server needs you to prove who you are before it will show the page, and it did not receive valid credentials. It is usually caused by a password gate or an expired login key.

What is the difference between a 401 and a 403 error?

A 401 says you are not authenticated, so the right login might get you in. A 403 says access is refused even if the server knows who you are. 401 problems are usually about credentials; 403 problems are usually about permissions or firewall rules.

Why is my website asking for a username and password?

Most often a folder or site-wide password was added during development or on a staging copy and never removed, or a security feature protects the login page with an extra password. Your host or developer can tell you which.

Why does the WordPress REST API return 401?

The request did not include valid credentials, or something removed them. Common causes are revoked Application Passwords, a security plugin restricting the REST API, or a server setup that strips the login header before WordPress sees it.

Will a 401 error hurt my Google rankings?

Yes, if it covers public pages. Google cannot index pages that require a password, so pages stuck behind a 401 will drop out of search results until the gate is removed.

Can I fix a 401 error myself?

Often. Removing a leftover folder password in cPanel or regenerating an app key is well within reach. If the prompt comes from server configuration you cannot see, your host or a developer will need to find it.

Related free guides

WordPress site down?

Seeing “There has been a critical error on this website”?

Our guided repair tool logs in over secure FTPS and fixes the most common WordPress failures — safely, with every change backed up and reversible. Start with a free scan, no password needed.

Fix My WordPress Site → Free scan · No download of your site · Reversible