AdSense Placeholder
Slot: header_reference_page
Every HTTP response starts with a three-digit status code. The first digit is the class; the other two refine it. This page lists the codes you will meet most often. For all of them, with search, use the HTTP Status Code Lookup.
| Code |
Name |
Meaning |
100 |
Continue |
The client may continue sending the request body |
101 |
Switching Protocols |
Switching to another protocol, such as WebSocket |
2xx Success
| Code |
Name |
Meaning |
200 |
OK |
The request worked and the response carries the result |
201 |
Created |
Something new was created (typical for POST) |
202 |
Accepted |
Accepted for processing, not finished yet |
204 |
No Content |
Success with no body to return (typical for DELETE) |
206 |
Partial Content |
Only the byte range you asked for (resumable downloads, video) |
3xx Redirection
| Code |
Name |
Meaning |
301 |
Moved Permanently |
Moved for good: update links and bookmarks |
302 |
Found |
Temporarily elsewhere: keep using the original URL |
303 |
See Other |
Go and GET another URL (used after a POST) |
304 |
Not Modified |
Not modified: use your cached copy |
307 |
Temporary Redirect |
Temporary redirect that keeps the method and body |
308 |
Permanent Redirect |
Permanent redirect that keeps the method and body |
4xx Client error
| Code |
Name |
Meaning |
400 |
Bad Request |
The request is malformed or invalid |
401 |
Unauthorized |
Not authenticated: credentials are missing or wrong |
403 |
Forbidden |
Authenticated but not allowed to do this |
404 |
Not Found |
Nothing exists at this URL |
405 |
Method Not Allowed |
The URL exists but not for this method |
406 |
Not Acceptable |
Cannot produce a response the client says it accepts |
408 |
Request Timeout |
The server gave up waiting for the request |
409 |
Conflict |
Conflicts with the current state (edit collision, duplicate) |
410 |
Gone |
Gone for good: stronger than 404 |
413 |
Content Too Large |
The request body is too large |
414 |
URI Too Long |
The URL is too long |
415 |
Unsupported Media Type |
The body's format (Content-Type) is not supported |
416 |
Range Not Satisfiable |
The requested byte range cannot be served |
418 |
I'm a Teapot |
The server is a teapot (an April Fools' joke, RFC 2324) |
422 |
Unprocessable Content |
Well-formed but semantically invalid (common in APIs) |
429 |
Too Many Requests |
Too many requests: rate limited, check Retry-After |
431 |
Request Header Fields Too Large |
The request headers are too large |
451 |
Unavailable For Legal Reasons |
Blocked for legal reasons |
5xx Server error
| Code |
Name |
Meaning |
500 |
Internal Server Error |
A generic server-side failure |
501 |
Not Implemented |
The server does not support this feature or method |
502 |
Bad Gateway |
A gateway or proxy got a bad answer from upstream |
503 |
Service Unavailable |
Temporarily unavailable (overload, maintenance) |
504 |
Gateway Timeout |
A gateway or proxy timed out waiting for upstream |
505 |
HTTP Version Not Supported |
The HTTP version is not supported |
Easily confused pairs
- 401 vs 403.
401 means "I do not know who you are" (log in, or your token is wrong or expired). 403 means "I know who you are, and the answer is no".
- 301 vs 302 vs 307 vs 308. The permanent pair is
301 and 308; the temporary pair is 302 and 307. The newer 307 and 308 guarantee the request method and body are repeated unchanged, while old clients may turn a 301 or 302 POST into a GET.
- 404 vs 410. Both mean "not here".
410 says it was removed deliberately and will not return, which helps search engines drop the URL sooner.
- 502 vs 503 vs 504.
502: the upstream server answered badly. 503: the service is down or overloaded on purpose or by accident. 504: the upstream server did not answer in time.
- 400 vs 422.
400 is for requests the server cannot parse at all; 422 is for ones it parsed fine but cannot accept, such as a valid JSON body with an invalid email address.
Picking a code for an API
- Return
200 with a body for reads and updates, 201 with a Location header for creations and 204 when there is nothing to send back.
- Use
404 for a missing resource and 409 for a conflict, not 400 for everything.
- Use
401 only with an authentication challenge, and 403 for permission problems.
- Add
Retry-After to 429 and 503 so clients know when to try again.
- Do not hide errors behind
200: monitoring tools, caches and clients all rely on the status code.
Related reading: HTTP, Redirect, Rate limiting and HTTP Headers Cheat Sheet.