# 401 Authorization Required Response in API

**URL:** <https://community.perplexity.ai/t/401-authorization-required-response-in-api/2591>\
**Category:** Bug Reports\
**Created:** [November 12, 2025, 4:24pm UTC](https://community.perplexity.ai/t/401-authorization-required-response-in-api/2591 "2025-11-12T16:24:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![AlecFurrier](https://sea1.discourse-cdn.com/flex001/user_avatar/community.perplexity.ai/alecfurrier/32/1782_2.png) [@AlecFurrier](https://community.perplexity.ai/u/AlecFurrier)\
**Post date:** [November 12, 2025, 4:24pm UTC](https://community.perplexity.ai/t/401-authorization-required-response-in-api/2591/1 "2025-11-12T16:24:56Z")

</div>

My credits are burning but im getting 401s… why?

Here’s a fresh, first-hand capture of what happens when this backend calls Perplexity right now:

`REQUEST:`  
`{`  
` "model": "sonar",`  
` "messages": [`  
` {`  
` "role": "system",`  
` "content": "You are a concise news analyst. Always reply with raw JSON."`  
` },`  
` {`  
` "role": "user",`  
` "content": "Return a minimal JSON object with a hello message."`  
` }`  
` ],`  
` "temperature": 0.2,`  
` "max_tokens": 200`  
`}`

`RESPONSE STATUS: 401`  
`HEADERS:`  
` date: Wed, 12 Nov 2025 16:14:25 GMT`  
` content-type: text/html`  
` transfer-encoding: chunked`  
` connection: keep-alive`  
` cf-ray: 99d7527ecdf5e677-DEN`  
` cf-cache-status: DYNAMIC`  
` strict-transport-security: max-age=15552000; includeSubDomains; preload`  
` server: cloudflare`

`BODY (first 400 chars):`  
`<html>`  
`<head><title>401 Authorization Required</title></head>`  
`<body>`  
`<center><h1>401 Authorization Required</h1></center>`  
`<hr><center>openresty/1.27.4</center>`  
`<script>(function(){function c(){var b=a.contentDocument||a.contentWindow document ...`

So every request—including this simple test payload—gets intercepted by Cloudflare (note the cf-ray header and the HTML body). Perplexity counts the call as soon as it hits their edge, which is why credits go down even though the actual API never returns JSON.

This confirms the issue isn’t in our prompt or payload; the token is being blocked before it reaches the service. You’ll need to work with Perplexity to allow this key/IP (or rotate to a key with server-side access). Until then, any automated refresh will yield the same 401 HTML page while still consuming credits.

---

<div class="post-metadata">

**Author:** ![Noa\_Minter](https://sea1.discourse-cdn.com/flex001/user_avatar/community.perplexity.ai/noa_minter/32/2124_2.png) [@Noa\_Minter](https://community.perplexity.ai/u/Noa_Minter)\
**Post date:** [December 13, 2025, 8:04pm UTC](https://community.perplexity.ai/t/401-authorization-required-response-in-api/2591/2 "2025-12-13T20:04:52Z")

</div>

Having the same issue…

When you say you have to work with perplexity to resolve can you explain specifically what you mean?

I’m getting this through openrouter chat, every perplexity model

---

<div class="post-metadata">

**Author:** ![Gary\_Poduska](https://sea1.discourse-cdn.com/flex001/user_avatar/community.perplexity.ai/gary_poduska/32/1678_2.png) [@Gary\_Poduska](https://community.perplexity.ai/u/Gary_Poduska)\
**Post date:** [December 16, 2025, 4:48pm UTC](https://community.perplexity.ai/t/401-authorization-required-response-in-api/2591/3 "2025-12-16T16:48:08Z")

</div>

I am having the same issue. Any api call yields this error now!

---

<div class="post-metadata">

**Author:** ![August\_Dua](https://sea1.discourse-cdn.com/flex001/user_avatar/community.perplexity.ai/august_dua/32/2163_2.png) [@August\_Dua](https://community.perplexity.ai/u/August_Dua)\
**Post date:** [December 17, 2025, 3:37pm UTC](https://community.perplexity.ai/t/401-authorization-required-response-in-api/2591/4 "2025-12-17T15:37:13Z")

</div>

Same issue with sonar-deep-research

---

<div class="post-metadata">

**Author:** ![tobs-fbx](https://sea1.discourse-cdn.com/flex001/user_avatar/community.perplexity.ai/tobs-fbx/32/2590_2.png) [@tobs-fbx](https://community.perplexity.ai/u/tobs-fbx)\
**Post date:** [February 2, 2026, 2:30pm UTC](https://community.perplexity.ai/t/401-authorization-required-response-in-api/2591/5 "2026-02-02T14:30:42Z")

</div>

I guess I have the same problem accessing the API from Claude Code. See bug report below:

I’m unable to connect to the Perplexity API through the official MCP server (`@perplexity-ai/mcp-server`), receiving a 401 Unauthorized error with a Cloudflare challenge response.

**Environment:**

- OS: Windows 11

- Client: Claude Code (VS Code extension)

- MCP Package: `@perplexity-ai/mcp-server` (also tested community `perplexity-mcp`)

- API Key: `pplx-p3fj9hmT...` (regenerated fresh key, confirmed valid)

**Configuration (.mcp.json):**

```auto
{
  "perplexity": {
    "command": "npx",
    "args": ["-y", "@perplexity-ai/mcp-server"],
    "env": {
      "PERPLEXITY_API_KEY": "..."
    }
  }
}

```

**Symptoms:**

- All MCP calls return 401 with Cloudflare HTML challenge page (not a standard API error)

- Error contains: `openresty/1.27.4` and Cloudflare challenge script

**Troubleshooting completed:**

1. ✅ Verified API key works via direct curl:

2. ✅ Regenerated API key - same issue

3. ✅ Cleared npm cache (`npx clear-npx-cache`)

4. ✅ Tested both official and community MCP packages - same result

5. ✅ Other MCP servers (Exa, Firecrawl) work correctly in same environment

**Conclusion:**  
The API key and network can reach Perplexity (curl works), but requests from Node.js/npx environment are being blocked by Cloudflare bot protection.

**Request:**  
Please advise on how to resolve the Cloudflare blocking for MCP server connections.

Thank you.
