HTTP Status Codes
A searchable reference for every HTTP status code, in plain English.
Runs entirely in your browser.
Your data never leaves this device and is never sent to our servers.
100
Continue
The client should carry on with the request body. Sent after an Expect: 100-continue header.
101
Switching Protocols
The server is changing protocol as the client asked — the WebSocket handshake uses this.
200
OK
The request succeeded. For GET the body is the resource; for POST it is the result.
201
Created
A new resource exists. Return its URL in the Location header.
202
Accepted
Received but not yet processed. Use it for queued work.
204
No Content
Succeeded with nothing to return. The correct answer to a DELETE.
206
Partial Content
A range request succeeded. Used by video seeking and resumable downloads.
301
Moved Permanently
The resource has a new URL forever. Search engines transfer ranking to the target.
302
Found
A temporary redirect. The original URL keeps its ranking.
304
Not Modified
The cached copy is still valid, so no body is sent. This is what makes ETags worthwhile.
307
Temporary Redirect
Like 302, but the method must not change. A POST stays a POST.
308
Permanent Redirect
Like 301, but the method must not change.
400
Bad Request
The request is malformed. Do not use it for validation failures — 422 is more precise.
401
Unauthorized
Authentication is missing or invalid. Badly named: it means unauthenticated.
403
Forbidden
Authenticated, but not permitted. Identity is known; permission is refused.
404
Not Found
No resource at this URL. Also used to hide the existence of a resource from someone who should not know.
405
Method Not Allowed
The URL exists but not for this verb. Include an Allow header listing the ones that work.
409
Conflict
The request clashes with current state — a duplicate, or an edit against a stale version.
410
Gone
Deliberately removed and not coming back. Unlike 404, this tells crawlers to drop the URL.
413
Payload Too Large
The body exceeds what the server accepts.
415
Unsupported Media Type
The Content-Type is not one this endpoint handles.
418
I'm a Teapot
An April Fools joke from 1998 that survives in the standard. Never use it in production.
422
Unprocessable Content
Well-formed but semantically invalid — the right code for validation errors.
429
Too Many Requests
Rate limited. Send a Retry-After header so the client knows when to return.
500
Internal Server Error
The server failed and has nothing more specific to say. Check your logs.
502
Bad Gateway
An upstream server returned something invalid. Usually your app is down behind the proxy.
503
Service Unavailable
Temporarily unable to handle the request — overloaded or in maintenance.
504
Gateway Timeout
An upstream server did not respond in time.
HTTP status codes are the first thing an API tells a client, and choosing the wrong one causes real bugs — clients retry when they should not, or give up when they should retry.
The classes: 1xx informational, 2xx success, 3xx redirection, 4xx the client is at fault, 5xx the server is at fault.
How to use it
- Search by code number or by name.
- Filter by class to browse a whole group.
- Read the explanation, including the common misuses.
Not working as you expect? Report a problem with this tool.
Frequently asked questions
401 or 403?
401 means we do not know who you are — authenticate and try again. 403 means we know exactly who you are and you still may not. The names are misleading: 401 is really "unauthenticated".
400 or 422?
Use 400 when the request itself is malformed, such as broken JSON. Use 422 when it parsed fine but failed validation. Most APIs should return 422 for form errors.
301 or 302?
301 is permanent and transfers search ranking to the new URL. 302 is temporary and leaves ranking on the original. Using 302 for a permanent move is a common and costly SEO mistake.
404 or 410?
410 says the resource was deliberately deleted, so crawlers drop it faster. 404 just says it is not here, which could be temporary.