arkynChangelogGuides
docs / bad-responses / unauthorized

Unauthorized

The Unauthorized class represents an HTTP error response with status code 401. It is used to standardize "Unauthorized" error responses, typically when the user is not authenticated or the authentication credentials are invalid.

Import

ts

import { Unauthorized } from "@arkyn/server/unauthorized";
Learn how subpath and root imports differ in How do I use imports.

Constructor

  • message (required): A descriptive message explaining why the request is unauthorized.
  • cause (optional): Additional information about the error cause, which can be any serializable data.

Methods

toResponse() - Converts the instance into a Response object with JSON body and Content-Type: application/json header.
toJson() - Alternative method using Response.json() for generating the JSON error response.

Usage example

typescript

import { Unauthorized } from "@arkyn/server/unauthorized";
// Basic usage - throw the error
throw new Unauthorized("Authentication required");
// With cause information
throw new Unauthorized("Invalid token", {
tokenType: "JWT",
reason: "Token expired",
});
// Convert to Response object
const error = new Unauthorized("Please log in to continue");
return error.toResponse();
// Using toJson alternative
return error.toJson();

Response structure

The response body follows a standardized structure:

json

{
"name": "Unauthorized",
"message": "Authentication required"
}
This is sent with HTTP status 401, set on the Response object itself, the status code is not part of the JSON body.
If a cause is passed to the constructor, it is included in the body as well:

json

{
"name": "Unauthorized",
"message": "Invalid token",
"cause": "{\"tokenType\":\"JWT\",\"reason\":\"Token expired\"}"
}

Notes

When thrown, this class automatically emits a debug log to the console showing the file and function where the error originated. See DebugService to configure ignored files for accurate caller detection.
The cause parameter, when provided, is serialized with JSON.stringify() and included in the response body under the cause key, it is sent to clients, not just kept for server-side debugging. Because it's stringified, cause appears in the JSON body as a JSON-encoded string rather than a nested object.
Use Unauthorized (401) when the user is not authenticated. Use Forbidden (403) when the user is authenticated but lacks permission to access the resource.
Related in Bad responses
On this page
    arkyn