Developer Toolbox
4xx client errorNot retryable as isHeader: Allow

405 Method Not Allowed

The server knows this URL but doesn't accept the HTTP method used on it. It has to list the methods it does accept in an Allow header.

Open cURL Builder Rebuild the request with a method the Allow header lists.

Common causes

  • The route is defined for GET only and the client sends POST, or the other way round.
  • A redirect changed the method: most clients resend a POST that got a 301 or 302 as a GET, and the new URL only takes POST.
  • A missing trailing slash triggers exactly such a redirect, so the POST never arrives as a POST.
  • A static host or CDN in front of the app answers every POST with 405, because it only serves files.
  • The browser's CORS preflight sends OPTIONS, and the server has no handler for it.

How to fix it

  • Read the Allow header: it lists the methods this URL accepts.
  • Check which method the server received. If it logged a GET where you sent a POST, a redirect happened on the way: call the final URL directly, or make the redirect a 307 or 308.
  • Make sure the request reaches the application and not a static host in front of it: compare the Server header with a request that works.
  • For CORS, answer OPTIONS with a 204 and an Access-Control-Allow-Methods header.

405 or 501?

405 is about this URL: the server supports the method, just not here. 501 Not Implemented means it doesn't support the method anywhere, like a PROPFIND sent to a plain web server.

Example

POST /orders/81723 HTTP/1.1
Host: api.example.com

HTTP/1.1 405 Method Not Allowed
Allow: GET, PUT, DELETE
Content-Type: text/plain

Method Not Allowed

Defined in RFC 9110, section 15.5.6.