HTTP Status Code Reference

Searchable reference for every HTTP status code, explained simply.

Web

Understanding HTTP status codes

HTTP status codes are three-digit numbers returned by a web server in response to every HTTP request. They are defined in the HTTP specification (currently RFC 9110) and are grouped by their first digit into five classes, each with a distinct meaning.

1xx Informational codes indicate that the request was received and the process is continuing. The most common is 100 Continue, which tells a client that the request headers were accepted and it should proceed to send the body.

2xx Success codes indicate the request was successfully received, understood, and accepted. 200 OK is the standard success response. 201 Created means a resource was created (used after POST). 204 No Content means success with no response body (common after DELETE).

3xx Redirection codes indicate the client must take additional action to complete the request. 301 Moved Permanently is used for permanent URL changes (SEO-important). 302 Found is a temporary redirect. 304 Not Modified means the cached version is current.

4xx Client Error codes indicate the client made a bad request. 400 Bad Request is the generic client error. 401 Unauthorized means authentication is required. 403 Forbidden means the client is authenticated but not authorized. 404 Not Found means the resource does not exist. 429 Too Many Requests is used for rate limiting.

5xx Server Error codes indicate the server failed to fulfil a valid request. 500 Internal Server Error is the generic server error. 502 Bad Gateway means an upstream service returned an invalid response. 503 Service Unavailable means the server is temporarily overloaded or down for maintenance.

Common mistakes

  • Using 200 for errors — Returning HTTP 200 with an error body (sometimes called "200 OK with error") makes API clients impossible to write correctly. Use appropriate 4xx/5xx codes.
  • 401 vs 403 confusion — 401 means "you need to authenticate." 403 means "you are authenticated but not allowed." Many APIs misuse these.
  • Returning 404 for all errors — Returning 404 for authentication failures, validation errors, or server errors hides the true nature of the problem from clients and logging systems.