Mock XML endpoint returning HTTP 401
https://demo-xml-401.supercrontab.com/ answers every request with HTTP 401 Unauthorized and a small XML body. No signup, CORS enabled, nothing logged. Use it to see how your client, retry logic or cron job behaves on a 401 before it happens in production.
Live demo endpoint
Any method, any path. Returns 401 Unauthorized with Content-Type: application/xml. OPTIONS returns 204 with CORS headers.
Call it with curl
curl -i https://demo-xml-401.supercrontab.com/
Call it with fetch
const res = await fetch("https://demo-xml-401.supercrontab.com/");
console.log(res.status); // 401
const body = await res.text();What HTTP 401 Unauthorized means
- When you see it
- No credentials were sent, or the token is expired or invalid. Common after an API key rotation.
- What a client should do
- Refresh or re-issue the token, then retry once. Repeated 401s mean the key itself is wrong.
- Retry?
- No
Sample response body
<?xml version="1.0" encoding="UTF-8"?> <response> <ok>true</ok> <id>42</id> </response>
Common in SOAP, payment and legacy enterprise APIs. Good for testing XML parsers and namespaces.
Questions
Does this endpoint really return HTTP 401 every time?
Yes. Every GET, POST, PUT, PATCH or DELETE to https://demo-xml-401.supercrontab.com/ gets status 401 Unauthorized with a small XML body, whatever the path, query or headers. OPTIONS gets 204 with CORS headers so browsers can preflight.
Should my client retry a 401?
No. Retrying the same request cannot change the outcome. Refresh or re-issue the token, then retry once. Repeated 401s mean the key itself is wrong.
Can I get a different format, a delay or a custom body?
The same status is available in JSON, Text, CSV, HTML, YAML, RSS, JavaScript. Delays, custom headers, error rates, request logging and your own body need a personal endpoint: sign up and create one at /endpoints in a minute, free.