405 Method Not Allowed: why the server rejects your GET or POST

The address exists but not for that method. Read the Allow header, then check for redirects that turn POST into GET, static hosting and CORS preflights.

· 3 min read · By the Spot Downtime team

405 Method Not Allowed means the address exists, but not for the kind of request you sent. You POSTed to something that only accepts GET, or sent DELETE to a route that doesn't support it. It's a narrow error, which makes it quick to fix once you know where to look.

Start with the Allow header

A correct 405 response lists the methods that would have worked:

bash
curl -i -X DELETE https://api.example.com/orders

HTTP/2 405
allow: GET, POST

If your method is in that list and you still get 405, something in front of your app is answering instead.

Common causes

The wrong method in the client

Calling fetch(url) without { method: "POST" } sends a GET. An HTML form without method="post" sends a GET too. Check the request in your browser's network tab: the method is the first column.

A redirect turned POST into GET

If http:// redirects to https://, or /api/orders to /api/orders/, with a 301 or 302, most clients repeat the request as a GET. The final endpoint then rejects it. Call the final URL directly, or use 307/308 redirects, which keep the method.

Redirect checkerSee whether a URL redirects before it answers, and with which status code.

Static hosting

nginx, S3 and most static hosts serve files only for GET and HEAD. Posting a form to a static page returns 405. The form needs an action that points at a real backend or a form service.

The route isn't registered for that method

Frameworks return 405 when the path matches a route but the method doesn't, for example a Next.js route handler that exports GET but not POST, or an Express app with app.get where you needed app.post.

CORS preflight

Before some cross-origin requests, browsers send an OPTIONS request. If the server doesn't handle OPTIONS, the preflight fails with 405 and the browser reports a CORS error. Handle OPTIONS for those routes, or let your CORS middleware do it.

Monitoring an API endpoint

Health checks default to GET. If the endpoint you want to watch only accepts POST, the monitor needs to send a POST, with a body if required, or it will report a 405 forever. Spot Downtime's API monitors let you choose the method, headers and body.

Keep reading