Developers
Get access

Unauthorised

The request had no token, or its token is invalid, expired or for a login that has been revoked.

Status
401 Unauthorized
Type
https://developers.checkmystreet.co.uk/errors/unauthorised
Charged
No
Retry
Yes, once with a new token. If a fresh token is refused too, the login itself is the problem.

Example

{
  "type": "https://developers.checkmystreet.co.uk/errors/unauthorised",
  "title": "Unauthorised",
  "status": 401,
  "detail": "The token is invalid or has expired. Fetch a new one."
}

The response also carries the standard HTTP challenge: WWW-Authenticate: Bearer when the request had no token, and WWW-Authenticate: Bearer error="invalid_token" when its token is invalid, expired or revoked.

What to do

  • Fetch a new token from the token URL with your client id and secret, then send the request again with the same Idempotency-Key.
  • Cache tokens for their 30 minute lifetime, and fetch a new one when a call returns 401 rather than one per call.
  • Send the token as Authorization: Bearer <token>. A test token makes test calls and a live token live ones.
  • If a fresh token is refused too, the login may have been revoked: check it in the console, and see Authentication.

Related