Absolutely, the client will take care of the HTTP code, 401 means "not authorized", and there is no value in sending something else.
Think of it this way, what else could you send to a customer who could help?
You cannot give them more details, as this will become a security issue. So, don't worry about it, stick to 401 and no response body. Customers can handle this on their own.
source
share