The challenge header names what to send next.

highlighted = computed this step

WWW-Authenticate names the challenge

The response row displays the challenge safely as Basic realm toy.

challenge header checked\text{challenge header checked}
Challenge headerThe missing Authorization request, challenge response, and checks are recomputed from pinned bytes.Challenge header - GET /private has no Authorization; response 401 Unauthorized names Basicsectionnamevaluecheckrequest linemethodGETparsedrequest linepath/privateparsedrequest lineversionHTTP/1.1parsedheaderHostapi.exampleexactheaderAuthorizationabsentabsentstatusversionHTTP/1.1parsedstatusstatus401 UnauthorizedchallengeheaderWWW-AuthenticateBasic realm toysafe display formheaderContent-Length0empty bodybodybyte length0countedchallengeschemeBasicparsedchallengerealm displaytoyparsedcheckAuthorization headerabsentmissingcheckstatus401 Unauthorizedchallengecheckchallenge schemeBasicBasiccheckrealmtoytoychecksent body bytes0empty

The exact response bytes are pinned

The trust boundary checks the quoted realm in the pinned response bytes before rendering.

response bytes checked\text{response bytes checked}
Challenge headerThe missing Authorization request, challenge response, and checks are recomputed from pinned bytes.Challenge header - GET /private has no Authorization; response 401 Unauthorized names Basicsectionnamevaluecheckrequest linemethodGETparsedrequest linepath/privateparsedrequest lineversionHTTP/1.1parsedheaderHostapi.exampleexactheaderAuthorizationabsentabsentstatusversionHTTP/1.1parsedstatusstatus401 UnauthorizedchallengeheaderWWW-AuthenticateBasic realm toysafe display formheaderContent-Length0empty bodybodybyte length0countedchallengeschemeBasicparsedchallengerealm displaytoyparsedcheckAuthorization headerabsentmissingcheckstatus401 Unauthorizedchallengecheckchallenge schemeBasicBasiccheckrealmtoytoychecksent body bytes0empty

The challenge has a scheme and a realm

Chapter two reads those two pieces separately.

scheme and realm\text{scheme and realm}
Challenge headerThe missing Authorization request, challenge response, and checks are recomputed from pinned bytes.Challenge header - GET /private has no Authorization; response 401 Unauthorized names Basicsectionnamevaluecheckrequest linemethodGETparsedrequest linepath/privateparsedrequest lineversionHTTP/1.1parsedheaderHostapi.exampleexactheaderAuthorizationabsentabsentstatusversionHTTP/1.1parsedstatusstatus401 UnauthorizedchallengeheaderWWW-AuthenticateBasic realm toysafe display formheaderContent-Length0empty bodybodybyte length0countedchallengeschemeBasicparsedchallengerealm displaytoyparsedcheckAuthorization headerabsentmissingcheckstatus401 Unauthorizedchallengecheckchallenge schemeBasicBasiccheckrealmtoytoychecksent body bytes0empty

Summary

The challenge header tells the client which auth style to try next.

challenge header parsed\text{challenge header parsed}
Challenge headerThe missing Authorization request, challenge response, and checks are recomputed from pinned bytes.Challenge header - GET /private has no Authorization; response 401 Unauthorized names Basicsectionnamevaluecheckrequest linemethodGETparsedrequest linepath/privateparsedrequest lineversionHTTP/1.1parsedheaderHostapi.exampleexactheaderAuthorizationabsentabsentstatusversionHTTP/1.1parsedstatusstatus401 UnauthorizedchallengeheaderWWW-AuthenticateBasic realm toysafe display formheaderContent-Length0empty bodybodybyte length0countedchallengeschemeBasicparsedchallengerealm displaytoyparsedcheckAuthorization headerabsentmissingcheckstatus401 Unauthorizedchallengecheckchallenge schemeBasicBasiccheckrealmtoytoychecksent body bytes0empty