Correct. You’re supposed to send 403 only when 1. you’ve successfully “logged in” with a set of credentials, but 2. the user that those credentials map to, doesn’t have rights on the resource. If you haven’t authed at all, and there’s a resource there requiring auth, you’re supposed to send 401.