HTTP 406 Not Acceptable
The server can’t produce a response in any format listed in the request’s Accept headers.
Meaning
Content negotiation failed: the client asked for, say, Accept: application/xml and the endpoint only produces JSON. On shared hosting, 406 is also a classic ModSecurity response to requests that look suspicious.
Common causes
- Accept header asks for a type the endpoint doesn’t produce
- Accept-Language / Accept-Encoding / Accept-Charset unsatisfiable
- ModSecurity/WAF rule on shared hosting blocking the request (often form posts containing code or SQL-like text)
- Spring/ASP.NET with no message converter for the requested type
⚡ Quick fix
- Send
Accept: application/json(or*/*) - On shared hosting, check the ModSecurity log / ask the host to whitelist the rule ID
- Add the right serializer/converter on the server
Detailed fix by platform
Java
- Spring: make sure Jackson is on the classpath and
produceson the mapping matches the Accept header.
Apache
- cPanel → ModSecurity: check hits for the domain; disable the specific rule ID rather than ModSecurity entirely.
Code examples
Compare Accept headers
bash
curl -i -H 'Accept: application/xml' https://api.example.com/items # 406
curl -i -H 'Accept: application/json' https://api.example.com/items # 200How to diagnose
- Accept headers — What did the client ask for?
- Producer — What can the endpoint return?
- WAF — Is ModSecurity or a WAF answering instead of the app?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026