HTTP Status Codes Reference

Search or filter every common HTTP status code. Each response from a web server starts with a three-digit code that says what happened.

CodeNameMeaning
100ContinueThe server received the request headers; the client should continue sending the body.
101Switching ProtocolsThe server agrees to switch protocols, for example to WebSocket.
103Early HintsLets the browser start preloading resources while the server prepares the full response.
200OKThe request succeeded. The meaning depends on the method: GET returns data, POST returns the result of the action.
201CreatedA new resource was created. Usually returned by POST or PUT, with a Location header pointing to it.
202AcceptedThe request was accepted for processing but is not finished yet (asynchronous work).
204No ContentSuccess, with no body to return. Common for DELETE and for updates that need no response data.
206Partial ContentOnly part of the resource is returned, in answer to a Range request (resuming downloads, video seeking).
301Moved PermanentlyThe resource has a new permanent URL. Search engines transfer ranking to the new address.
302FoundTemporary redirect. The client should keep using the original URL in future.
303See OtherRedirects to another URL with GET, typically after a form POST.
304Not ModifiedThe cached copy is still valid, so no body is sent. Saves bandwidth.
307Temporary RedirectLike 302, but the client must repeat the same method and body.
308Permanent RedirectLike 301, but the method and body must not change.
400Bad RequestThe server cannot understand the request because of malformed syntax or invalid data.
401UnauthorizedAuthentication is required or has failed. (Despite the name, it is about who you are.)
403ForbiddenThe server understood the request but refuses it. You are known but not allowed.
404Not FoundThe resource does not exist at this URL (or the server hides that it exists).
405Method Not AllowedThe URL exists but not for this HTTP method. The Allow header lists valid ones.
406Not AcceptableThe server cannot produce a response matching the Accept headers sent.
408Request TimeoutThe server gave up waiting for the client to finish sending the request.
409ConflictThe request conflicts with the current state of the resource, such as an edit collision or duplicate.
410GoneThe resource used to exist and was removed on purpose. Stronger than 404.
411Length RequiredThe request needs a Content-Length header.
413Content Too LargeThe request body exceeds what the server will accept.
414URI Too LongThe URL is longer than the server is willing to process.
415Unsupported Media TypeThe request body format (Content-Type) is not supported.
418I'm a teapotAn April Fools joke from RFC 2324; some APIs return it for playful refusals.
422Unprocessable ContentThe request is well-formed but contains semantic errors, such as failed validation.
425Too EarlyThe server will not risk processing a request that might be replayed.
426Upgrade RequiredThe client must switch to a different protocol (e.g. newer TLS).
428Precondition RequiredThe server requires the request to be conditional (If-Match) to avoid lost updates.
429Too Many RequestsRate limit exceeded. Check the Retry-After header and slow down.
431Request Header Fields Too LargeThe headers (often cookies) are too big.
451Unavailable For Legal ReasonsAccess is blocked because of a legal demand, such as censorship or a court order.
500Internal Server ErrorA generic server-side failure: something unexpected broke. Check the server logs.
501Not ImplementedThe server does not support the functionality needed to fulfil the request.
502Bad GatewayA gateway or proxy received an invalid response from the upstream server.
503Service UnavailableThe server is temporarily overloaded or down for maintenance. Retry later (see Retry-After).
504Gateway TimeoutA gateway or proxy did not get a timely response from the upstream server.
505HTTP Version Not SupportedThe server does not support the HTTP version used.
507Insufficient StorageThe server cannot store the representation needed to complete the request.
511Network Authentication RequiredThe client must authenticate to gain network access, such as captive portals on public Wi-Fi.

The five classes

  • 1xx - informational: the request is still being processed.
  • 2xx - success: the request worked.
  • 3xx - redirection: look somewhere else.
  • 4xx - client error: the request has a problem (wrong URL, no permission, bad data).
  • 5xx - server error: the server failed on a valid request.

401 vs 403

401 means "I do not know who you are - log in". 403 means "I know who you are and you may not do this". For a resource you want to hide completely, some sites deliberately return 404 instead of 403.

301 vs 302 and SEO

Use 301 (or 308) when a page has moved for good so search engines pass ranking to the new URL; use 302 (or 307) for temporary moves such as maintenance or A/B tests.

Debugging tips

  • 4xx: re-check the URL, method, headers, authentication and request body.
  • 5xx: look at the server logs first; the client usually cannot fix it.
  • 429: slow down and honour the Retry-After header; add exponential backoff.
  • 502/504: the problem is between a proxy and the app behind it - check that the app is running and not timing out.