## TL;DR

Security plugins like Wordfence can also block the header, so test with them disabled. When both fail, the cause is often the server stripping the Authorization header before it reaches WordPress (ModSecurity, firewall rules, or host config).

## Steps

1. When WooCommerce REST calls 401, first confirm youre sending exactly one auth method. If both Application Passwords and API keys fail identically, ask the host whether anything strips the Authorization header. Security plugins like Wordfence can also block the header, so test with them disabled.

## When to use

You are seeing this: When WooCommerce REST calls 401, first confirm youre sending exactly one auth method. Use this skill when you run into "WooCommerce REST 401s: use one auth method, and check the server passes the header".

## When not to use

If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.

## Versions

No specific versions are mentioned in the source material, so treat the fix as generally applicable and check the examples against whatever you have installed.

## Why this happens

The original report does not dig into a root cause. It documents the symptom and the fix that resolved it.
