HTTP 401 Unauthorized vs 506 Variant Also Negotiates
HTTP 401 (Unauthorized) is a 4xx Client Error response, while 506 (Variant Also Negotiates) is a 5xx Server Error response. 401 indicates that the request requires user authentication. The response includes a WWW-Authenticate header indicating the authentication scheme. In contrast, 506 means that the server has an internal configuration error: the chosen variant resource is configured to engage in content negotiation itself.
Description
The request requires user authentication. The response includes a WWW-Authenticate header indicating the authentication scheme.
When You See It
When accessing a protected resource without credentials or with expired tokens.
How to Fix
Include valid authentication credentials (API key, Bearer token, Basic auth) in the Authorization header.
Description
The server has an internal configuration error: the chosen variant resource is configured to engage in content negotiation itself.
When You See It
Rare. Indicates a misconfigured server-side content negotiation loop.
How to Fix
Fix the server's content negotiation configuration.
Key Differences
401 is a 4xx Client Error response, while 506 is a 5xx Server Error response.
HTTP 401: The request requires user authentication. The response includes a WWW-Authenticate header indicating the authentication scheme.
HTTP 506: The server has an internal configuration error: the chosen variant resource is configured to engage in content negotiation itself.
You encounter 401 when when accessing a protected resource without credentials or with expired tokens.
You encounter 506 when rare. Indicates a misconfigured server-side content negotiation loop.
When to Use Which
For 401 (Unauthorized): Include valid authentication credentials (API key, Bearer token, Basic auth) in the Authorization header. For 506 (Variant Also Negotiates): Fix the server's content negotiation configuration.