< HTTP/1.1 511 Network Authentication Required511 Network Authentication Required: Captive Portals
511 is returned by a network gateway, such as hotel or airport Wi-Fi, that requires login before granting internet access. Learn how apps should handle it.
- Cacheable
- Only with explicit freshness
- Retry?
- After authenticating to the network (captive portal)
- Usually sent by
- Network gateway (captive portal)
- Spec
- RFC 6585 §6
- Often confused with
- 401
TL;DR: 511 comes from a Wi-Fi gateway or network proxy that wants you to log in before any traffic passes. It is never the website’s response. Apps should treat it as “network not ready”, not retry blindly, and send the user to a browser to authenticate.
What it means
Public Wi-Fi in hotels, airports and cafes intercepts HTTP requests and answers them itself until the user accepts terms. RFC 6585 §6 defines 511 so clients can recognise the interception, instead of getting a 200 with a login page and trying to parse it as the API they asked for. The RFC says the response should include a link to the login page, and must not be sent by origin servers.
HTTP/1.1 511 Network Authentication Required
Content-Type: text/html
Cache-Control: no-store
<html>
<head>
<title>Network Authentication Required</title>
<meta http-equiv="refresh" content="0; url=https://login.hotel-wifi.example/">
</head>
<body>
<p>You need to <a href="https://login.hotel-wifi.example/">authenticate with the local network</a> to gain access.</p>
</body>
</html>
The redirect is in the body (a meta refresh or a link), not a Location header, so that a client that treats 3xx as “follow transparently” does not leak the original request to the portal.
What actually happens in practice
Many portals do not use 511. They return 302 to a login page, or 200 with HTML, or hijack DNS. That is why your API client may see:
SyntaxError: Unexpected token '<', "<!DOCTYPE "... is not valid JSON
or a TLS certificate error for a HTTPS request that the portal tried to intercept. HTTPS is not interceptable without a certificate warning, so the portal sees the failure and relies on the OS to open a login sheet via its own detection probe.
Operating systems detect portals by fetching a URL with a known answer:
curl -i http://connectivitycheck.gstatic.com/generate_204
# open network: HTTP/1.1 204 No Content
# captive: 200 / 302 / 511 with a portal page instead
Handling it in an app
- Treat
511as “network requires sign-in”. Show a message and a button to open the browser. Do not display the portal HTML, and never send credentials to the host that returned it. - Do not retry in a tight loop and do not mark the endpoint as down in your own monitoring: it is the user’s network.
- If a response that should be JSON is HTML, or the host you reached presented an unexpected certificate, suspect a captive portal before suspecting your backend.
- Do not cache:
Cache-Control: no-storeon 511 bodies prevents the login page being stored as your resource. - If you run a captive portal gateway, return 511 for non-browser HTTP requests (those without
Accept: text/html) and keep HTTP/HTTPS interception to the minimum the OS probes require. RFC 8910 offers a cleaner approach: advertise the portal URL through DHCP or router advertisements so clients do not rely on interception.
Related
- 407 Proxy Authentication Required: a proxy wants credentials, you know about it.
- 401 Unauthorized
- 403 Forbidden
- 502 Bad Gateway
Frequently asked questions
What does 511 Network Authentication Required mean?
A network intermediary between you and the internet, typically public Wi-Fi, is intercepting your traffic until you log in or accept terms. The response comes from the gateway, not from the website you requested.
Why does my app get an HTML login page instead of JSON?
The hotspot captive portal answered your API request with its own page. Compliant gateways use 511 so clients can recognise it; many send 200 or a 302 redirect, which is why an API client sees a successful but wrong response.
Should my server ever send 511?
No. RFC 6585 says origin servers must not generate it. It is reserved for the intercepting network proxy that controls access to the network.
Can I cache or retry a 511?
Do not cache it, and do not retry in a loop. The request will keep failing until the user completes the login in a browser; after that retry the original request.
How do apps detect captive portals?
Operating systems request a known URL and expect an exact reply: Android fetches connectivitycheck.gstatic.com/generate_204 and expects 204, and Apple devices fetch captive.apple.com and expect a specific Success page. Anything else marks the network as captive.
Sources
Related
508 Loop Detected: Proxy and Redirect Loops
508 Loop Detected means the server found an infinite loop while processing a request. Learn the WebDAV origin, proxy loops, CDN-Loop and how to find the cycle.
521 Web Server Is Down
Cloudflare-specific status code indicating the origin server refused the connection. Learn about this proxy error and how to troubleshoot it.
501 Not Implemented
The server doesn't support the functionality required to fulfill the request. Learn about unimplemented features.
504 Gateway Timeout: nginx, ALB and Cloudflare Fixes
Fix 504 Gateway Timeout: nginx proxy_read_timeout (60s default), ALB 60s idle, API Gateway 29s, Cloudflare 524 at 125s, with error-log strings and curl timing.