Recall when to return 401, 403, or 404 for protected REST resources.
Login problem When is 401 Unauthorized the right response? When the request does not have valid authentication credentials. The caller’s next move is authenticate or refresh credentials. Permission problem When is 403 Forbidden the right response? When the caller is authenticated but not allowed to perform the action. Use it when revealing the resource or permission boundary is acceptable. Enumeration objection “But 403 is more honest when the project exists.” Cross-tenant project IDs in a SaaS API. Your line Honesty to an unauthorized tenant can become an existence leak; return the same 404 for nonexistent and cross-tenant objects. Different codes…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in