Ffile2fix
Sign in Get started

How to fix "405 Method Not Allowed"

405 Not Allowed
nginx

A 405 means the server found the URL but does not accept the HTTP method you used, such as POST, PUT or DELETE. The most common cause is a form or API call sending POST to a URL that only accepts GET, or Nginx serving a static file for a POST request.

Also appears as: 405 Method Not Allowed · The method is not allowed for the requested URL. · HTTP Error 405.0 - Method Not Allowed · The POST method is not supported for this route. Supported methods: GET, HEAD.

Common causes

  • A form or fetch() call uses POST but the route only accepts GET (or the reverse)
  • Nginx serves a static .html file for a POST request, which it never allows
  • A trailing slash redirect turns a POST into a GET
  • A framework route is missing for that method (Laravel, Express, Flask)
  • IIS WebDAV module intercepts PUT and DELETE requests
  • A WAF or security rule blocks methods like PUT, PATCH or DELETE

How to fix it

  1. Check the method and URL. Open developer tools > Network, find the failing request, and note its method and exact URL. Look at the Allow response header, which lists methods the server accepts.
  2. Match the route definition. Make sure your app defines a route for that method, for example Route::post('/contact', ...) in Laravel or app.post('/contact', ...) in Express.
  3. Point forms at a script, not a static file. If the form action is a .html file, Nginx returns 405 for POST. Point it at a PHP script or app route that processes the data.
  4. Avoid redirects on POST. Use the exact URL, including or excluding the trailing slash as the server expects. A 301 redirect makes browsers resend the request as GET.
  5. Disable WebDAV on IIS if unused. On IIS, remove the WebDAVModule and WebDAV handler in web.config so PUT and DELETE reach your app.
  6. Review security rules. Check ModSecurity, your CDN firewall or Nginx limit_except blocks for rules that deny the method.

Check which methods a URL allows

curl -i -X OPTIONS https://example.com/api/items
# Look for the Allow: header in the response

How to stop it happening again

  • Keep routes and front-end calls in sync
  • Use consistent trailing slash rules for API endpoints
  • Test each HTTP method in your API tests
  • Document which methods each endpoint supports

Frequently asked questions

What is the difference between 404 and 405?

404 means the URL does not exist. 405 means the URL exists but does not accept the method you used.

Why does my contact form give 405 on Nginx?

Nginx will not accept POST to a static file. Send the form to a PHP script or backend route instead.

Can a redirect cause a 405?

Yes. A 301 or 302 redirect turns POST into GET, which may hit a route that only accepts POST. Use the final URL or a 307/308 redirect.