Skip to content

HTTP Status Codes Explained

Every common HTTP response status code, grouped by class: what it means and when you'll see it. The quick-reference companion to the HTTP Status Codes tool.

HTTP status codes share one pattern: the first digit names the class, and the rest is detail. 1xx means informational, 2xx means success, 3xx means redirection, 4xx means the client made an error, and 5xx means the server failed. Read the first digit first. The companion tool lets you look up a single code in depth.

Reference table · 55 entriesOpen the http-status-codes tool →
55 of 55 rows
1xx Informational
ContinueThe server received the request headers and the client may send the body.After a preflight check before uploading a large body.
Switching ProtocolsThe server agrees to switch to the protocol the client requested.Upgrading an HTTP connection to WebSocket.
ProcessingThe server received the request and is still working on it.A WebDAV server acknowledging a long request so the client does not time out.
Early HintsThe server sends preliminary headers before the final response is ready.Letting a browser preload assets while the page is still being rendered.
2xx Success
OKThe request succeeded and the response body carries the result.Standard success for a GET or PUT.
CreatedThe request succeeded and a new resource was created.Return after a successful POST that makes something.
AcceptedThe request was accepted for processing but is not finished yet.A long-running job has started and runs asynchronously.
Non-Authoritative InformationThe request succeeded but the returned data was transformed on the way back.A proxy or cache serving modified metadata instead of the origin's.
No ContentThe request succeeded and there is no body to return.A DELETE succeeded, or a PUT with nothing to say.
Reset ContentThe request succeeded and the client should reset the view that sent it.After a form submit, telling the page to clear its fields.
Partial ContentThe server is returning only part of the resource as requested.Serving a byte range from a Range request.
3xx Redirection
Moved PermanentlyThe resource has a permanent new URL and future requests should use it.A page moved and search engines must update their index.
FoundThe resource is temporarily at a different URL, but keep using the original one.Redirecting to a login page for a moment.
See OtherThe answer lives at a different URL and must be fetched with a GET.The PRG pattern: redirect a POST to a result page so a refresh does not resubmit.
Not ModifiedThe cached copy is still valid, so the server sends no body.Conditional GET where the client's cache is up to date.
Use ProxyThe request must be sent through the proxy named in the response.Legacy proxy networks; deprecated since 2011.
Temporary RedirectThe resource is temporarily elsewhere and the original request method must be preserved.Like 302, but a POST stays a POST on the redirect.
Permanent RedirectThe resource has a permanent new URL and the original request method must be preserved.Like 301, but a POST stays a POST on the redirect.
4xx Client error
Bad RequestThe server could not understand the request due to malformed syntax.Malformed JSON, or a missing required field.
UnauthorizedAuthentication is required and was either missing or failed.No token, or an invalid or expired token.
Payment RequiredThe request requires payment, though the spec never defined how.Some APIs use it as a paywall marker; most never use it.
ForbiddenThe client is authenticated but is not allowed to access this resource.Valid login, but no permission for this resource.
Not FoundThe server has no resource at this URL.Unknown URL or an ID that does not exist.
Method Not AllowedThe URL exists but does not allow the request method used.A POST against an endpoint that only accepts GET.
Not AcceptableThe server cannot return content that matches the client's Accept headers.The client asked for XML only, but the API only returns JSON.
Proxy Authentication RequiredThe client must authenticate with the proxy before the request goes on.A corporate proxy rejecting an unauthenticated request.
Request TimeoutThe client took too long to send the request and the server gave up.An upload that stalled before the body finished arriving.
ConflictThe request conflicts with the current state of the resource.A duplicate email or an edit race on the same record.
GoneThe resource existed once but has been removed permanently.An endpoint retired on purpose, stronger than 404.
Length RequiredThe request needs a Content-Length header and does not have one.A server that must know the size upfront rejecting a streamed body.
Precondition FailedA header precondition such as If-Match evaluated to false.An optimistic edit where the record changed since the client read it.
Content Too LargeThe request body exceeds the limit the server accepts.An upload bigger than the server's maximum body size.
URI Too LongThe request URL is longer than the server is willing to interpret.A form accidentally serialized into a GET query string that grew without bound.
Unsupported Media TypeThe request body format is not one the endpoint accepts.A POST with Content-Type text/plain against a JSON-only endpoint.
Range Not SatisfiableThe byte range in the Range header does not fit the resource.Asking for bytes past the end of a file when resuming a download.
Expectation FailedThe server cannot meet the expectation stated in the Expect header.A 100-continue expectation the server refuses to honor.
I'm a teapotThe server is a teapot and refuses to brew coffee.An April Fools' joke from 1998 that will not die; APIs return it for fun.
Misdirected RequestThe request was sent to a server that cannot produce a response for it.A reused connection sent to a host this server does not serve.
Unprocessable EntityThe request is well-formed but its values fail semantic validation.Valid JSON whose fields violate business rules.
Too EarlyThe server refuses a request that risks being a replay.Rejecting a retried non-idempotent request before keys are rotated.
Upgrade RequiredThe client must switch to a different protocol to use this resource.An endpoint that insists on TLS or WebSocket.
Precondition RequiredThe server requires conditional headers the request did not send.An API demanding If-Match to prevent lost updates.
Too Many RequestsThe client has sent too many requests in a given time window.A rate limit was hit; back off and retry.
Request Header Fields Too LargeOne or more header fields are too large for the server to process.A cookie or token that grew until it blocked every request to the site.
Unavailable For Legal ReasonsThe resource is blocked for legal reasons, such as a takedown or a geo-restriction.A government takedown or a page blocked in one country.
5xx Server error
Internal Server ErrorThe server hit an unexpected condition and failed.An unhandled exception or bug on the server.
Not ImplementedThe server does not support the method or feature requested.An endpoint is declared but not yet built.
Bad GatewayA gateway or proxy received an invalid response from an upstream server.A reverse proxy could not reach the backend.
Service UnavailableThe server is temporarily unable to handle the request.Maintenance, overload, or a dependent service being down.
Gateway TimeoutA gateway or proxy did not get a response in time from an upstream server.The backend took too long and the proxy gave up.
HTTP Version Not SupportedThe server does not support the HTTP version in the request.A client speaking a protocol version the server never learned.
Variant Also NegotiatesTransparent content negotiation ended in a circular reference.A misconfigured server doing experimental content negotiation.
Insufficient StorageThe server cannot store the representation needed to complete the request.A WebDAV server whose allocated storage is full.
Loop DetectedThe server hit an infinite loop while processing the request.A WebDAV binding that refers back to itself.
Network Authentication RequiredThe client must authenticate with the network to gain access.A captive portal at a hotel or airport intercepting the request.