# Expressive 401 response with application/json content type

**URL:** <https://discourse.laminas.dev/t/expressive-401-response-with-application-json-content-type/1188>\
**Category:** Mezzio\
**Tags:** authentication\
**Created:** [September 10, 2019, 6:36pm UTC](https://discourse.laminas.dev/t/expressive-401-response-with-application-json-content-type/1188 "2019-09-10T18:36:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vaclav\_Vanik](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/vaclav_vanik/32/539_2.png) [@Vaclav\_Vanik](https://discourse.laminas.dev/u/Vaclav_Vanik)\
**Post date:** [September 10, 2019, 6:36pm UTC](https://discourse.laminas.dev/t/expressive-401-response-with-application-json-content-type/1188/1 "2019-09-10T18:36:08Z")

</div>

401 http responses generated by [Expressive\Authentication\BasicAccess](https://github.com/zendframework/zend-expressive-authentication-basic/blob/41d34bb55cc4f03665e51fecdbb6ea800ac55434/src/BasicAccess.php) have `Content-type: text/html; charset=UTF-8`. I would like to return `application/json`.

- One way is to create custom BasicAccessFactory.
- Second way is to modify BasicAccessFactory to pull custom $responseFactory from $container if provided in config under `authentication`.

Your opinions?

---

<div class="post-metadata">

**Author:** ![marcguyer](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/marcguyer/32/132_2.png) [@marcguyer](https://discourse.laminas.dev/u/marcguyer)\
**Post date:** [September 17, 2019, 8:35pm UTC](https://discourse.laminas.dev/t/expressive-401-response-with-application-json-content-type/1188/2 "2019-09-17T20:35:51Z")

</div>

Curious what you did here. The default response factory in Expressive produces simply an empty `Zend\Diactoros\Response` which does not come with a `content-type` out of the box. So something else is adding that header – maybe via content negotiation. My sense tells me that manipulating the content type via the `BasicAccessFactory` isn’t ideal. I wonder if you ran a request with a proper json `Accept` header if you’d get the json `content-type` in the response.
