Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
HTTP 405 Method Not Allowed means the server recognizes the request method—such as POST, PUT or DELETE—but the particular resource at the requested URL does not support it. The route may exist and still reject that method. Check the response’s Allow header, then compare the exact method and URL with the endpoint’s API contract or server route declaration.
What HTTP 405 means
RFC 9110 defines 405 this way: “The 405 (Method Not Allowed) status code indicates that the method received in the request-line is known by the origin server but not supported by the target resource.” In practical terms, the server understood the method, but that method is not available for the resource identified by this request.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
High Performance Browser Networking: What every web developer should know about networking and web... | $31.84 | Buy on Amazon |
| 2 |
|
Learning HTTP/2: A Practical Guide for Beginners | $18.11 | Buy on Amazon |
| 3 |
|
HTTP: The Definitive Guide | $26.04 | Buy on Amazon |
| 4 |
|
HTTP Pocket Reference: Hypertext Transfer Protocol | $6.94 | Buy on Amazon |
| 5 |
|
HTTP/2 in Action | $49.99 | Buy on Amazon |
For example, an API may let a client retrieve an item with GET /api/items but not create one with POST /api/items. If the client sends POST to that URL and the resource currently permits only GET and HEAD, the server can respond with 405. The path can be valid; the method-to-path combination is not.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →405 is a 4xx client-error status, but that does not prove the caller alone is at fault. The caller may have used the wrong method or URL, or the server may have a route configuration that does not match the intended API contract. It does not, by itself, mean the whole server is down.
#1 Best Overall
- Used Book in Good Condition
Read the Allow header
An origin server generating a 405 response is required by RFC 9110 to include an Allow header. It lists the methods currently supported by the target resource, separated by commas. For example:
HTTP/1.1 405 Method Not Allowed
Allow: GET, HEAD
This response says that GET and HEAD are currently advertised as allowed for the resource, while the method the caller tried is not. Use that information alongside the API documentation and route configuration: the header is a diagnostic clue, not a substitute for confirming what the endpoint is meant to do. Allowed methods can change dynamically. An empty Allow value can indicate that the resource is temporarily disabled by configuration.
If the documented operation should be supported but the header does not list its method, inspect the server’s route registration and any proxy or gateway between the caller and application. Do not add a method or change the client request until you have confirmed the intended endpoint behavior.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #2
405 compared with 404, 501 and 403
| Status | What it communicates | What to check |
|---|---|---|
| 405 Method Not Allowed | The method is recognized but is not supported for this target resource. The response should include Allow. |
Whether the method and URL match the endpoint contract and route declaration. |
| 404 Not Found | The response concerns whether the server has a current representation for the target resource. | The host, path, version prefix, path parameters and trailing slash. |
| 501 Not Implemented | The method is unrecognized or not implemented by the server; RFC 9110 distinguishes this from a recognized method disallowed for one resource. | Whether the method is supported by the server at all, rather than merely omitted from this resource. |
| 403 Forbidden | Typically communicates an authorization or access-policy restriction, rather than method support. | Authentication and authorization policy, as well as the endpoint contract. |
These codes describe different conditions. Do not treat them as interchangeable or “fix” a 405 by returning another status without verifying what happened. In particular, changing POST to GET can change an operation that modifies data into a read request; choose the method that matches the operation’s semantics.
Common causes in an application
Method does not match the route
Frameworks commonly register handlers by both path and method. Express, for example, has separate declarations such as app.get() and app.post(); a handler runs when the request matches both the route path and HTTP method. A POST sent to a path registered only for GET therefore does not match that method handler.
Django REST framework likewise can return 405 for a method that a view does not permit, with a detail message such as Method 'DELETE' not allowed. Django’s HttpResponseNotAllowed takes the permitted methods, for example ['GET', 'POST']. Inspect the view’s declarations and permitted methods rather than assuming that the existence of a URL means every method works there.
Rank #3
Wrong or slightly different URL
A wrong API version prefix, host, path parameter or trailing slash can send a request to a different route than intended. That route may exist but permit a different method. Compare the complete URL—not just the final path segment—with the API specification and the route declaration.
Proxy, gateway or middleware changes the request
A reverse proxy or gateway may rewrite the URL or filter methods. Middleware can also intercept a request before it reaches the expected handler. These are possibilities to verify in logs and configuration, not reasons to assume a particular product is responsible. Comparing a public request with one sent directly to the application, where possible, helps identify whether behavior changes between those layers.
Browser form or request construction differs from what you expect
A browser form can default to GET when the server expects POST. An API client, application or script can also send a method different from the one used in a manual test. Capture the request actually sent; do not diagnose from the intended method alone.
Rank #4
How to troubleshoot a 405 step by step
- Capture the full exchange. Record the exact method, complete URL, status, response headers and response body using browser developer tools,
curl -ior an API client. The method and URL together identify the request that was rejected. - Inspect
Allow. Note the methods advertised for this resource. Treat the value as the server’s current indication, and compare it with the API contract; permitted methods can change dynamically. - Check the contract and URL. Verify the documented method, host, API version, path parameters and trailing slash. Confirm that the request is going to the intended environment and resource.
- Confirm route registration. In Express, inspect the relevant
app.get,app.postand other method-specific declarations. In Django or Django REST framework, inspect view method decorators,@api_viewdeclarations, routers and permitted-method lists. - Compare direct and proxied requests. If you can safely call the application without the reverse proxy or gateway, compare its response with the public one. A difference points toward URL rewriting or method filtering in an intermediary; inspect its configuration and logs.
- Check other request controls after method matching. Review authentication, CSRF, CORS and content-type handling where relevant. These controls may produce different errors or intercept a request, but changing them blindly can hide a route mismatch rather than solve it.
- Retest using the contract’s method. If the intended method is missing from the route, either correct the client request or deliberately implement the method. Before adding a write or delete operation, verify authorization, input validation and side effects.
Example: diagnosing POST to an API route
Suppose the client sends:
POST /api/items HTTP/1.1
Host: example.test
Content-Type: application/json
{}
The response is 405 Method Not Allowed with Allow: GET, HEAD. The immediate finding is that the target resource currently advertises GET and HEAD, not POST. Next, check whether the client has the right URL and whether the API contract says this URL accepts POST. If it does, inspect the route registration and any intermediary that might be rewriting or filtering the request. If the contract specifies another URL for creation, send the POST there instead.
Do not switch to GET merely to make the status disappear if the intended operation creates or changes data. That would change the request’s meaning, not correct the underlying mismatch.
Or skip the browser setup
For a visual check of a page, ScreenshotNeo can return a screenshot or PDF through one GET request; it is not a replacement for checking API response headers or server route logs when diagnosing a 405. Cookie banners are accepted and removed before capture, and newsletter popups and chat widgets are removed; each cleanup step can be turned off. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, with response headers reporting the page verdict and billing status. Its MCP server gives AI agents tools to take screenshots, get page information and capture PDFs. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots.
ScreenshotNeo API documentation
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.test/api/items -o shot.webp
This captures a visual rendering where the target is a page; it does not establish which HTTP methods an API route supports. See ScreenshotNeo for product details, or sign up free for 1,000 screenshots a month with no card.
Best Value
What to keep in mind
- A 405 means the method is recognized but is not supported for the requested resource.
- The required
Allowheader lists methods currently supported by that resource. - A route can exist while rejecting a particular method.
- 501 concerns an unrecognized or unimplemented method; 405 concerns a recognized method disallowed for this resource.
- Check the request, route and any intermediary before changing authorization or adding a handler.
Frequently Asked Questions
Does HTTP 405 mean the website is offline?
No. It indicates that the server answered but does not support the requested method for that resource; it does not establish that the entire server is unavailable.
Can a 405 response have an empty Allow header?
Yes. An empty value can indicate that the resource is temporarily disabled by configuration.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

