1xx Informational ⤢ 100Continue The server received the request headers and the client may send the body. After a preflight check before uploading a large body. ⤢ 101Switching Protocols The server agrees to switch to the protocol the client requested. Upgrading an HTTP connection to WebSocket. ⤢ 102Processing The server received the request and is still working on it. A WebDAV server acknowledging a long request so the client does not time out. ⤢ 103Early Hints The server sends preliminary headers before the final response is ready. Letting a browser preload assets while the page is still being rendered. 2xx Success ⤢ 200OK The request succeeded and the response body carries the result. Standard success for a GET or PUT. ⤢ 201Created The request succeeded and a new resource was created. Return after a successful POST that makes something. ⤢ 202Accepted The request was accepted for processing but is not finished yet. A long-running job has started and runs asynchronously. ⤢ 203Non-Authoritative Information The request succeeded but the returned data was transformed on the way back. A proxy or cache serving modified metadata instead of the origin's. ⤢ 204No Content The request succeeded and there is no body to return. A DELETE succeeded, or a PUT with nothing to say. ⤢ 205Reset Content The request succeeded and the client should reset the view that sent it. After a form submit, telling the page to clear its fields. ⤢ 206Partial Content The server is returning only part of the resource as requested. Serving a byte range from a Range request. 3xx Redirection ⤢ 301Moved Permanently The resource has a permanent new URL and future requests should use it. A page moved and search engines must update their index. ⤢ 302Found The resource is temporarily at a different URL, but keep using the original one. Redirecting to a login page for a moment. ⤢ 303See Other The answer lives at a different URL and must be fetched with a GET. The PRG pattern: redirect a POST to a result page so a refresh does not resubmit. ⤢ 304Not Modified The cached copy is still valid, so the server sends no body. Conditional GET where the client's cache is up to date. ⤢ 305Use Proxy The request must be sent through the proxy named in the response. Legacy proxy networks; deprecated since 2011. ⤢ 307Temporary Redirect The resource is temporarily elsewhere and the original request method must be preserved. Like 302, but a POST stays a POST on the redirect. ⤢ 308Permanent Redirect The resource has a permanent new URL and the original request method must be preserved. Like 301, but a POST stays a POST on the redirect. 4xx Client error ⤢ 400Bad Request The server could not understand the request due to malformed syntax. Malformed JSON, or a missing required field. ⤢ 401Unauthorized Authentication is required and was either missing or failed. No token, or an invalid or expired token. ⤢ 402Payment Required The request requires payment, though the spec never defined how. Some APIs use it as a paywall marker; most never use it. ⤢ 403Forbidden The client is authenticated but is not allowed to access this resource. Valid login, but no permission for this resource. ⤢ 404Not Found The server has no resource at this URL. Unknown URL or an ID that does not exist. ⤢ 405Method Not Allowed The URL exists but does not allow the request method used. A POST against an endpoint that only accepts GET. ⤢ 406Not Acceptable The server cannot return content that matches the client's Accept headers. The client asked for XML only, but the API only returns JSON. ⤢ 407Proxy Authentication Required The client must authenticate with the proxy before the request goes on. A corporate proxy rejecting an unauthenticated request. ⤢ 408Request Timeout The client took too long to send the request and the server gave up. An upload that stalled before the body finished arriving. ⤢ 409Conflict The request conflicts with the current state of the resource. A duplicate email or an edit race on the same record. ⤢ 410Gone The resource existed once but has been removed permanently. An endpoint retired on purpose, stronger than 404. ⤢ 411Length Required The request needs a Content-Length header and does not have one. A server that must know the size upfront rejecting a streamed body. ⤢ 412Precondition Failed A header precondition such as If-Match evaluated to false. An optimistic edit where the record changed since the client read it. ⤢ 413Content Too Large The request body exceeds the limit the server accepts. An upload bigger than the server's maximum body size. ⤢ 414URI Too Long The request URL is longer than the server is willing to interpret. A form accidentally serialized into a GET query string that grew without bound. ⤢ 415Unsupported Media Type The request body format is not one the endpoint accepts. A POST with Content-Type text/plain against a JSON-only endpoint. ⤢ 416Range Not Satisfiable The byte range in the Range header does not fit the resource. Asking for bytes past the end of a file when resuming a download. ⤢ 417Expectation Failed The server cannot meet the expectation stated in the Expect header. A 100-continue expectation the server refuses to honor. ⤢ 418I'm a teapot The server is a teapot and refuses to brew coffee. An April Fools' joke from 1998 that will not die; APIs return it for fun. ⤢ 421Misdirected Request The request was sent to a server that cannot produce a response for it. A reused connection sent to a host this server does not serve. ⤢ 422Unprocessable Entity The request is well-formed but its values fail semantic validation. Valid JSON whose fields violate business rules. ⤢ 425Too Early The server refuses a request that risks being a replay. Rejecting a retried non-idempotent request before keys are rotated. ⤢ 426Upgrade Required The client must switch to a different protocol to use this resource. An endpoint that insists on TLS or WebSocket. ⤢ 428Precondition Required The server requires conditional headers the request did not send. An API demanding If-Match to prevent lost updates. ⤢ 429Too Many Requests The client has sent too many requests in a given time window. A rate limit was hit; back off and retry. ⤢ 431Request Header Fields Too Large One or more header fields are too large for the server to process. A cookie or token that grew until it blocked every request to the site. ⤢ 451Unavailable For Legal Reasons The resource is blocked for legal reasons, such as a takedown or a geo-restriction. A government takedown or a page blocked in one country. 5xx Server error ⤢ 500Internal Server Error The server hit an unexpected condition and failed. An unhandled exception or bug on the server. ⤢ 501Not Implemented The server does not support the method or feature requested. An endpoint is declared but not yet built. ⤢ 502Bad Gateway A gateway or proxy received an invalid response from an upstream server. A reverse proxy could not reach the backend. ⤢ 503Service Unavailable The server is temporarily unable to handle the request. Maintenance, overload, or a dependent service being down. ⤢ 504Gateway Timeout A gateway or proxy did not get a response in time from an upstream server. The backend took too long and the proxy gave up. ⤢ 505HTTP Version Not Supported The server does not support the HTTP version in the request. A client speaking a protocol version the server never learned. ⤢ 506Variant Also Negotiates Transparent content negotiation ended in a circular reference. A misconfigured server doing experimental content negotiation. ⤢ 507Insufficient Storage The server cannot store the representation needed to complete the request. A WebDAV server whose allocated storage is full. ⤢ 508Loop Detected The server hit an infinite loop while processing the request. A WebDAV binding that refers back to itself. ⤢ 511Network Authentication Required The client must authenticate with the network to gain access. A captive portal at a hotel or airport intercepting the request.