HTTP status codes
The first digit carries the meaning: 1xx is informational, 2xx succeeded, 3xx needs another request, 4xx blames the request, 5xx blames the server. Picking the right one matters because clients, proxies and caches act on the class without reading your body.
28 entries
1xx — Informational
| Code | Name | Meaning | |
|---|---|---|---|
| 100 | Continue | The headers are acceptable; send the body. | |
| 101 | Switching Protocols | Upgrading, typically to WebSocket. | |
| 103 | Early Hints | Preload hints while the real response is prepared. |
2xx — Success
| Code | Name | Meaning | |
|---|---|---|---|
| 200 | OK | Standard success with a body. | |
| 201 | Created | A new resource exists. Include its Location header. | |
| 202 | Accepted | Queued for processing; the outcome is not yet known. | |
| 204 | No Content | Success with deliberately no body. Common for DELETE. | |
| 206 | Partial Content | A range request succeeded. Used by resumable downloads. |
3xx — Redirection
| Code | Name | Meaning | |
|---|---|---|---|
| 301 | Moved Permanently | Permanent. Caches and search engines will remember it — hard to undo. | |
| 302 | Found | Temporary, but may change the method to GET. Prefer 307. | |
| 303 | See Other | Fetch the result elsewhere with GET. The POST-redirect-GET pattern. | |
| 304 | Not Modified | The cached copy is still valid. No body is sent. | |
| 307 | Temporary Redirect | Temporary and preserves the method and body. | |
| 308 | Permanent Redirect | Permanent and preserves the method and body. |
4xx — Client error
| Code | Name | Meaning | |
|---|---|---|---|
| 400 | Bad Request | Malformed. The catch-all when nothing more specific fits. | |
| 401 | Unauthorized | Not authenticated — despite the name. Send WWW-Authenticate. | |
| 403 | Forbidden | Authenticated but not allowed. Re-authenticating will not help. | |
| 404 | Not Found | No such resource. Also used to hide the existence of one. | |
| 405 | Method Not Allowed | Wrong verb for this resource. Must include Allow. | |
| 409 | Conflict | Clashes with current state — a duplicate, or a failed optimistic lock. | |
| 410 | Gone | Deliberately removed, permanently. Stronger than 404. | |
| 422 | Unprocessable Content | Syntax is fine, semantics are not. Validation failures. | |
| 429 | Too Many Requests | Rate limited. Include Retry-After. |
5xx — Server error
| Code | Name | Meaning | |
|---|---|---|---|
| 500 | Internal Server Error | Something broke and it was not the client's fault. | |
| 501 | Not Implemented | The method is not supported at all. | |
| 502 | Bad Gateway | An upstream returned something invalid. | |
| 503 | Service Unavailable | Temporarily down or overloaded. Include Retry-After. | |
| 504 | Gateway Timeout | An upstream did not answer in time. |
401 versus 403 is the pair most often swapped: 401 means we do not know who you are, 403 means we do and the answer is still no.