401 Unauthorized Error: Why Your Site Is Asking for a Password
Visitors see "401 Unauthorized" or a browser pop-up asking for a username and password — the server wants proof of who you are before it will show the page, and the proof is missing or wrong.
Common signs of this issue
- Pages show "401 Unauthorized", "HTTP Error 401", or "Authorization Required" instead of your content.
- A plain grey browser box pops up asking for a username and password before the site or wp-admin loads.
- The live site was fine until someone launched it from a staging copy, and now everyone gets a password prompt.
- Your own login works, but a plugin, app, or integration reports a 401 when it connects to your site.
- The WordPress editor will not save and shows an error, while the browser's developer tools mention 401.
- Search Console says some pages are blocked due to unauthorized request (401).
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Note exactly where it happens: the whole site, one folder, only wp-admin, only the login page, or only a connected app. A 401 that covers a single folder or area almost always traces back to one setting.
- If you see a grey browser pop-up rather than a styled page, that is HTTP authentication (sometimes called basic auth). Ask your developer or host whether a password was added to a folder or the whole site, and try any "staging" or "preview" credentials you were once given.
- In cPanel, open Directory Privacy (called Password Protect Directories in older versions) and look for your site's folder or wp-admin marked as protected. That shows whether a folder password is in place — make a note before changing anything.
- If the site was recently copied from staging, check your host's staging or site tools for a password protection toggle. Several managed WordPress hosts password-protect staging and development copies by default, and that setting sometimes follows the site to live. See using a staging site for how the two copies should relate.
- If only the login page asks for an extra password, look in your security plugin or host panel for a login protection or HTTP auth for wp-login feature. It may be doing its job — find out who set it and what the credentials are before removing it.
- For editor save failures in WordPress, open Tools, then Site Health and check the REST API test. A 401 there, together with an editor error like "not a valid JSON response", points to a security plugin, firewall rule, or folder password blocking the editor's background requests.
- For apps and integrations, check the credentials first: regenerate the WordPress Application Password or the service's API key, and paste it in fresh. Expired or mistyped keys are the most common cause of a 401 from an integration.
- Clear cookies for your own site and log in again. A stale login session can cause 401 responses in the dashboard that disappear once you sign in cleanly.
What this usually means
A 401 means "I do not know who you are." The server is not refusing you outright; it is asking for credentials and either got none or got ones it did not accept. That is different from a 403 Forbidden error, which means "I know what you are asking for and you are not allowed it," regardless of login. The practical difference: a 401 is usually fixed by supplying the right credentials or removing a password gate, while a 403 is usually fixed by changing permissions or firewall rules.
On small business sites, the most common cause is a password gate that was meant to be temporary. A developer protected the site while building it, the host protected a staging copy, or someone added a folder password in cPanel, and the protection was never removed when the site went live. Visitors then hit a browser pop-up they cannot answer. The second big group is login-page hardening: a security plugin or host feature adding a second password prompt in front of wp-login.php. That is a legitimate defense, but it causes confusion when nobody wrote down the extra credentials.
The quieter kind of 401 happens behind the scenes. The WordPress editor, mobile apps, backup services, and tools like Zapier talk to your site through its REST API, and they must prove who they are on every request. If an Application Password was revoked, a security plugin blocks REST access for non-logged-in requests, or the server strips the login header before WordPress sees it, those tools get a 401 while the site looks fine in a browser. If you cannot log in at all, start with WordPress admin login not working instead.
What not to do
- Don't delete .htaccess or .htpasswd files blindly. They may hold other important rules, and some protections were put there on purpose.
- Don't turn off your security plugin entirely to get past a login prompt. Adjust the one setting that is causing the 401.
- Don't share staging or folder passwords in public places such as forum posts or unencrypted shared documents.
- Don't keep guessing at a password pop-up. Repeated failures can trigger lockouts at your host or firewall.
- Don't assume a 401 in an app means the site is hacked. Expired or revoked credentials are far more likely.
- Don't leave a staging site unprotected to fix the problem. Remove the gate from the live site, not from staging.
When to get help
Bring in help when you cannot tell where the password gate lives, when it came from a site launch you did not handle yourself, or when a 401 is breaking the editor, a store integration, or backups. Password prompts can come from the server configuration, the host panel, Cloudflare Access, or a plugin, and removing the wrong layer can either do nothing or strip away protection you need. Someone who can see the server config and the site together finds the real gate quickly and removes only what should go.
Glenn, who runs WebsiteSelfHelp, fixes unexpected password prompts and 401 errors for small business websites, from leftover staging protection to broken API connections. Describe where the prompt or error shows up, and you will get an honest read on the cause and what it will take to clear it — no passwords needed to get started.
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
What does 401 Unauthorized mean?
It means the server needs you to prove who you are before it will show the page, and it did not receive valid credentials. It is usually caused by a password gate or an expired login key.
What is the difference between a 401 and a 403 error?
A 401 says you are not authenticated, so the right login might get you in. A 403 says access is refused even if the server knows who you are. 401 problems are usually about credentials; 403 problems are usually about permissions or firewall rules.
Why is my website asking for a username and password?
Most often a folder or site-wide password was added during development or on a staging copy and never removed, or a security feature protects the login page with an extra password. Your host or developer can tell you which.
Why does the WordPress REST API return 401?
The request did not include valid credentials, or something removed them. Common causes are revoked Application Passwords, a security plugin restricting the REST API, or a server setup that strips the login header before WordPress sees it.
Will a 401 error hurt my Google rankings?
Yes, if it covers public pages. Google cannot index pages that require a password, so pages stuck behind a 401 will drop out of search results until the gate is removed.
Can I fix a 401 error myself?
Often. Removing a leftover folder password in cPanel or regenerating an app key is well within reach. If the prompt comes from server configuration you cannot see, your host or a developer will need to find it.