Unauthorized class represents an HTTP error response with status code 401. It is used to standardize "Unauthorized" error responses, typically when the user is not authenticated or the authentication credentials are invalid.ts
import { Unauthorized } from "@arkyn/server/unauthorized";
message (required): A descriptive message explaining why the request is unauthorized.cause (optional): Additional information about the error cause, which can be any serializable data.toResponse() - Converts the instance into a Response object with JSON body and Content-Type: application/json header.toJson() - Alternative method using Response.json() for generating the JSON error response.typescript
import { Unauthorized } from "@arkyn/server/unauthorized";// Basic usage - throw the errorthrow new Unauthorized("Authentication required");// With cause informationthrow new Unauthorized("Invalid token", {tokenType: "JWT",reason: "Token expired",});// Convert to Response objectconst error = new Unauthorized("Please log in to continue");return error.toResponse();// Using toJson alternativereturn error.toJson();
json
{"name": "Unauthorized","message": "Authentication required"}
401, set on the Response object itself, the status code is not part of the JSON body.cause is passed to the constructor, it is included in the body as well:json
{"name": "Unauthorized","message": "Invalid token","cause": { "tokenType": "JWT", "reason": "Token expired" }}
cause parameter, when provided, is included in the response body under the cause key as-is, it is sent to clients, not just kept for server-side debugging. Since v3.0.12, cause is no longer serialized with JSON.stringify() first, it's stored and returned exactly as passed (an object stays a nested object, not a JSON-encoded string). See Breaking Changes.cause is omitted from the response body entirely when NODE_ENV === "production", to avoid leaking internal error detail to clients. message and name are unaffected in every environment. See Breaking Changes.Unauthorized (401) when the user is not authenticated. Use Forbidden (403) when the user is authenticated but lacks permission to access the resource.