Cheat Sheets Web & HTTP

HTTP Status Codes Cheat Sheet

The HTTP status codes you will actually meet, grouped by class, with the pairs people confuse (401 vs 403, 301 vs 308) and tips for choosing codes in an API.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page
On this page

Every HTTP response starts with a three-digit status code. The first digit is the class; the other two refine it. This page lists the codes you will meet most often. For all of them, with search, use the HTTP Status Code Lookup.

1xx Informational

Code Name Meaning
100 Continue The client may continue sending the request body
101 Switching Protocols Switching to another protocol, such as WebSocket

2xx Success

Code Name Meaning
200 OK The request worked and the response carries the result
201 Created Something new was created (typical for POST)
202 Accepted Accepted for processing, not finished yet
204 No Content Success with no body to return (typical for DELETE)
206 Partial Content Only the byte range you asked for (resumable downloads, video)

3xx Redirection

Code Name Meaning
301 Moved Permanently Moved for good: update links and bookmarks
302 Found Temporarily elsewhere: keep using the original URL
303 See Other Go and GET another URL (used after a POST)
304 Not Modified Not modified: use your cached copy
307 Temporary Redirect Temporary redirect that keeps the method and body
308 Permanent Redirect Permanent redirect that keeps the method and body

4xx Client error

Code Name Meaning
400 Bad Request The request is malformed or invalid
401 Unauthorized Not authenticated: credentials are missing or wrong
403 Forbidden Authenticated but not allowed to do this
404 Not Found Nothing exists at this URL
405 Method Not Allowed The URL exists but not for this method
406 Not Acceptable Cannot produce a response the client says it accepts
408 Request Timeout The server gave up waiting for the request
409 Conflict Conflicts with the current state (edit collision, duplicate)
410 Gone Gone for good: stronger than 404
413 Content Too Large The request body is too large
414 URI Too Long The URL is too long
415 Unsupported Media Type The body's format (Content-Type) is not supported
416 Range Not Satisfiable The requested byte range cannot be served
418 I'm a Teapot The server is a teapot (an April Fools' joke, RFC 2324)
422 Unprocessable Content Well-formed but semantically invalid (common in APIs)
429 Too Many Requests Too many requests: rate limited, check Retry-After
431 Request Header Fields Too Large The request headers are too large
451 Unavailable For Legal Reasons Blocked for legal reasons

5xx Server error

Code Name Meaning
500 Internal Server Error A generic server-side failure
501 Not Implemented The server does not support this feature or method
502 Bad Gateway A gateway or proxy got a bad answer from upstream
503 Service Unavailable Temporarily unavailable (overload, maintenance)
504 Gateway Timeout A gateway or proxy timed out waiting for upstream
505 HTTP Version Not Supported The HTTP version is not supported

Easily confused pairs

  • 401 vs 403. 401 means "I do not know who you are" (log in, or your token is wrong or expired). 403 means "I know who you are, and the answer is no".
  • 301 vs 302 vs 307 vs 308. The permanent pair is 301 and 308; the temporary pair is 302 and 307. The newer 307 and 308 guarantee the request method and body are repeated unchanged, while old clients may turn a 301 or 302 POST into a GET.
  • 404 vs 410. Both mean "not here". 410 says it was removed deliberately and will not return, which helps search engines drop the URL sooner.
  • 502 vs 503 vs 504. 502: the upstream server answered badly. 503: the service is down or overloaded on purpose or by accident. 504: the upstream server did not answer in time.
  • 400 vs 422. 400 is for requests the server cannot parse at all; 422 is for ones it parsed fine but cannot accept, such as a valid JSON body with an invalid email address.

Picking a code for an API

  • Return 200 with a body for reads and updates, 201 with a Location header for creations and 204 when there is nothing to send back.
  • Use 404 for a missing resource and 409 for a conflict, not 400 for everything.
  • Use 401 only with an authentication challenge, and 403 for permission problems.
  • Add Retry-After to 429 and 503 so clients know when to try again.
  • Do not hide errors behind 200: monitoring tools, caches and clients all rely on the status code.

Related reading: HTTP, Redirect, Rate limiting and HTTP Headers Cheat Sheet.

Try these tools

See also

  • Glossary HTTP
    HTTP (Hypertext Transfer Protocol) is the protocol browsers and servers use to request and send web pages, files and data.
  • Glossary Redirect
    A redirect is a server response that sends the browser to a different URL, using a 3xx status code and a Location header.
  • Glossary Rate limiting
    Rate limiting restricts how many requests a client can make to a service in a given time, to protect it from overload and abuse.
  • Cheat sheet HTTP Headers Cheat Sheet
    Request and response headers, Cache-Control directives, security headers, cookie attributes and CORS headers.
AdSense Placeholder
Slot: footer_leaderboard