Would it be more appropriate (and specific, so more helpful to the client) to use 401 status when we're unable to validate the API token?
Would it be more appropriate (and specific, so more helpful to the client) to use 401 status when we're unable to validate the API token?