How HTTP Works
5xx · Server error
< HTTP/1.1 511 Network Authentication Required

511 Network Authentication Required: Captive Portals

511 is returned by a network gateway, such as hotel or airport Wi-Fi, that requires login before granting internet access. Learn how apps should handle it.

Reviewed 2 min readintermediate3 sourcesTry itMarkdown
Cacheable
Only with explicit freshness
Retry?
After authenticating to the network (captive portal)
Usually sent by
Network gateway (captive portal)
Spec
RFC 6585 §6
Often confused with
401
On this page

TL;DR: 511 comes from a Wi-Fi gateway or network proxy that wants you to log in before any traffic passes. It is never the website’s response. Apps should treat it as “network not ready”, not retry blindly, and send the user to a browser to authenticate.

What it means

Public Wi-Fi in hotels, airports and cafes intercepts HTTP requests and answers them itself until the user accepts terms. RFC 6585 §6 defines 511 so clients can recognise the interception, instead of getting a 200 with a login page and trying to parse it as the API they asked for. The RFC says the response should include a link to the login page, and must not be sent by origin servers.

HTTP/1.1 511 Network Authentication Required
Content-Type: text/html
Cache-Control: no-store

<html>
  <head>
    <title>Network Authentication Required</title>
    <meta http-equiv="refresh" content="0; url=https://login.hotel-wifi.example/">
  </head>
  <body>
    <p>You need to <a href="https://login.hotel-wifi.example/">authenticate with the local network</a> to gain access.</p>
  </body>
</html>

The redirect is in the body (a meta refresh or a link), not a Location header, so that a client that treats 3xx as “follow transparently” does not leak the original request to the portal.

What actually happens in practice

Many portals do not use 511. They return 302 to a login page, or 200 with HTML, or hijack DNS. That is why your API client may see:

SyntaxError: Unexpected token '<', "<!DOCTYPE "... is not valid JSON

or a TLS certificate error for a HTTPS request that the portal tried to intercept. HTTPS is not interceptable without a certificate warning, so the portal sees the failure and relies on the OS to open a login sheet via its own detection probe.

Operating systems detect portals by fetching a URL with a known answer:

curl -i http://connectivitycheck.gstatic.com/generate_204
# open network: HTTP/1.1 204 No Content
# captive:      200 / 302 / 511 with a portal page instead

Handling it in an app

  • Treat 511 as “network requires sign-in”. Show a message and a button to open the browser. Do not display the portal HTML, and never send credentials to the host that returned it.
  • Do not retry in a tight loop and do not mark the endpoint as down in your own monitoring: it is the user’s network.
  • If a response that should be JSON is HTML, or the host you reached presented an unexpected certificate, suspect a captive portal before suspecting your backend.
  • Do not cache: Cache-Control: no-store on 511 bodies prevents the login page being stored as your resource.
  • If you run a captive portal gateway, return 511 for non-browser HTTP requests (those without Accept: text/html) and keep HTTP/HTTPS interception to the minimum the OS probes require. RFC 8910 offers a cleaner approach: advertise the portal URL through DHCP or router advertisements so clients do not rely on interception.

Frequently asked questions

What does 511 Network Authentication Required mean?

A network intermediary between you and the internet, typically public Wi-Fi, is intercepting your traffic until you log in or accept terms. The response comes from the gateway, not from the website you requested.

Why does my app get an HTML login page instead of JSON?

The hotspot captive portal answered your API request with its own page. Compliant gateways use 511 so clients can recognise it; many send 200 or a 302 redirect, which is why an API client sees a successful but wrong response.

Should my server ever send 511?

No. RFC 6585 says origin servers must not generate it. It is reserved for the intercepting network proxy that controls access to the network.

Can I cache or retry a 511?

Do not cache it, and do not retry in a loop. The request will keep failing until the user completes the login in a browser; after that retry the original request.

How do apps detect captive portals?

Operating systems request a known URL and expect an exact reply: Android fetches connectivitycheck.gstatic.com/generate_204 and expects 204, and Apple devices fetch captive.apple.com and expect a specific Success page. Anything else marks the network as captive.

Sources

  1. MDN Web Docs: 511 Network Authentication Requireddeveloper.mozilla.org
  2. RFC 6585 Section 6: 511 Network Authentication Requiredrfc-editor.org
  3. RFC 8910: Captive-Portal Identification in DHCP and Router Advertisementsrfc-editor.org

Keep going

Browse /search