HTTP Status Codes Directory

Instant, searchable guide to standard HTTP response codes, their RFC definitions, and debugging tips.

What are HTTP Status Codes?

HTTP status codes are standard three-digit integers issued by a web server in response to a client request, standardized under IETF RFC 9110. They are divided into five classes: 1xx (Informational), 2xx (Successful), 3xx (Redirection), 4xx (Client Error), and 5xx (Server Error). These codes communicate request outcomes to browsers, APIs, and search engine crawlers.

1xx
Informational
2xx
Success
3xx
Redirection
4xx
Client Error
5xx
Server Error
100

Continue

RFC 9110

Server received initial request headers; client should proceed to send request body.

Common Cause: Sent in response to an Expect: 100-continue header.
How to Fix: Proceed sending the request payload.
101

Switching Protocols

RFC 9110

Server agrees to switch protocols as requested by client (e.g., HTTP to WebSocket).

Common Cause: Upgrade header requested WebSocket or HTTP/2.
How to Fix: Handshake completed; switch communication framing.
200

OK

RFC 9110

Standard response for successful HTTP requests.

Common Cause: Request was successfully understood and processed.
How to Fix: Normal operation; parse the response payload.
201

Created

RFC 9110

Request succeeded and led to creation of a new resource (usually POST/PUT).

Common Cause: Database or entity created successfully.
How to Fix: Inspect Location header for the new resource URL.
202

Accepted

RFC 9110

Request accepted for asynchronous processing, but processing is not completed.

Common Cause: Queued background jobs, batch uploads.
How to Fix: Poll the status endpoint or wait for a webhook.
204

No Content

RFC 9110

Request succeeded, but response body contains no content (e.g., DELETE).

Common Cause: Entity deleted or state updated without needing return payload.
How to Fix: Do not attempt to parse JSON body.
301

Moved Permanently

RFC 9110

Target resource has been assigned a new permanent URI.

Common Cause: URL restructure, domain migration, HTTP to HTTPS redirect.
How to Fix: Update bookmarks/links to the URL in Location header.
302

Found (Temporary Redirect)

RFC 9110

Target resource resides temporarily under a different URI.

Common Cause: Login redirects, temporary maintenance routes.
How to Fix: Follow Location header temporarily; keep original link.
304

Not Modified

RFC 9110

Cached version of resource is still fresh; no need to re-download body.

Common Cause: Client sent If-None-Match (ETag) or If-Modified-Since header.
How to Fix: Use local browser/CDN cache.
307

Temporary Redirect

RFC 9110

Redirects while preserving original HTTP method (e.g. POST remains POST).

Common Cause: Temporary route where request method cannot change.
How to Fix: Re-issue request with same HTTP method to new URL.
308

Permanent Redirect

RFC 9110

Permanent redirect while strictly preserving original HTTP method.

Common Cause: Permanent route where method must not change to GET.
How to Fix: Update links; retain HTTP method.
400

Bad Request

RFC 9110

Server cannot process request due to client error (malformed syntax, invalid JSON).

Common Cause: Syntax error in body, missing required params, invalid types.
How to Fix: Check request payload schema, header encodings, and types.
401

Unauthorized

RFC 9110

Authentication is required and has failed or not been provided.

Common Cause: Missing, expired, or invalid API key or Bearer token.
How to Fix: Refresh token or provide valid Authorization header.
403

Forbidden

RFC 9110

Server understands request but refuses to authorize it (insufficient permissions).

Common Cause: User is authenticated but lacks required role/scope.
How to Fix: Check user permissions, role-based access control, or IP blocklist.
404

Not Found

RFC 9110

Origin server cannot find current representation for target resource.

Common Cause: Broken URL, deleted item ID, incorrect endpoint path.
How to Fix: Verify URL spelling, path parameters, and route existence.
405

Method Not Allowed

RFC 9110

Target resource does not support the HTTP method used (e.g., POST on GET route).

Common Cause: Calling POST on a read-only endpoint.
How to Fix: Check Allow header and use the correct HTTP method.
408

Request Timeout

RFC 9110

Server closed connection because client took too long to send request.

Common Cause: Slow network, socket drop, stalled client stream.
How to Fix: Retry request with smaller payload or faster connection.
409

Conflict

RFC 9110

Request conflicts with current state of the resource (e.g., duplicate unique email).

Common Cause: Optimistic locking violation, unique constraint failure.
How to Fix: Resolve data conflict, fetch latest state, and retry.
410

Gone

RFC 9110

Resource existed previously but is permanently removed with no forwarding address.

Common Cause: Intentionally purged entity, expired promo code.
How to Fix: Remove client reference permanently; do not retry.
418

I'm a teapot

RFC 2324

RFC 2324 April Fools joke: The server refuses to brew coffee with a teapot.

Common Cause: HTCPCP protocol humorous Easter egg.
How to Fix: Brew tea instead.
422

Unprocessable Entity

RFC 9110

Request syntax is valid, but server was unable to process instructions (validation error).

Common Cause: Zod / Pydantic field validation failed, email format invalid.
How to Fix: Review response body error array and correct input fields.
429

Too Many Requests

RFC 6585

User has sent too many requests in a given amount of time (rate limited).

Common Cause: Exceeded API rate limit quota.
How to Fix: Check Retry-After header and implement exponential backoff.
500

Internal Server Error

RFC 9110

Server encountered an unexpected condition that prevented it from fulfilling request.

Common Cause: Unhandled exception, crash, database down, null pointer.
How to Fix: Inspect backend server logs and stack traces.
502

Bad Gateway

RFC 9110

Server acting as gateway/proxy received invalid response from inbound server.

Common Cause: Upstream application crashed, Nginx/Cloudflare cannot reach Node.js process.
How to Fix: Check upstream service health, port binding, and firewall.
503

Service Unavailable

RFC 9110

Server is currently unable to handle request due to overload or maintenance.

Common Cause: Server CPU/RAM maxed out, maintenance mode enabled.
How to Fix: Check Retry-After header; scale server instances.
504

Gateway Timeout

RFC 9110

Gateway/proxy did not receive timely response from upstream server.

Common Cause: Slow database query, unoptimized microservice request taking > 30s.
How to Fix: Optimize upstream query execution or increase proxy timeout.
505

HTTP Version Not Supported

RFC 9110

Server does not support, or refuses to support, the major HTTP version used.

Common Cause: Client used obsolete or unsupported HTTP protocol version.
How to Fix: Use HTTP/1.1 or HTTP/2.

Frequently Asked Questions

What is the difference between 401 Unauthorized and 403 Forbidden?+

A 401 Unauthorized response indicates authentication is required and has either failed or not yet been provided (missing or invalid Authorization header). A 403 Forbidden response indicates the server authenticates the caller identity, but the authenticated user lacks authorization or permissions to access the requested resource.

What is the difference between 301 Moved Permanently and 302 Found?+

A 301 redirect informs search engines and browsers that a resource has permanently relocated to a new URL, transferring SEO link equity and updating caches. A 302 redirect indicates a temporary relocation; search engine crawlers retain the original URL in indexes and browsers re-request the original URL in subsequent sessions.

How do I diagnose and fix a 502 Bad Gateway error?+

A 502 Bad Gateway occurs when an edge reverse proxy (such as NGINX, Cloudflare, or AWS ALB) receives an invalid or terminated response from an upstream backend application. To fix it, check upstream process status (Node.js/Python crashes), ensure internal listening ports match proxy configurations, and inspect backend error logs.

What does 429 Too Many Requests mean and how should clients handle it?+

HTTP 429 indicates that the client has exceeded rate limits within a given time window. Clients should inspect the 'Retry-After' response header to determine the required backoff duration (in seconds or as an HTTP date) before attempting retry requests, applying exponential backoff with jitter.

When should an API endpoint return 204 No Content instead of 200 OK?+

HTTP 204 No Content should be returned when an action succeeds (typically DELETE or PUT operations) but the response payload intentionally contains no body bytes. Browsers and HTTP clients receiving 204 do not update their active document view or attempt to parse JSON.

Testing API endpoints or translating HTTP requests?

Convert cURL commands to JavaScript Fetch, Axios, Python Requests, and Go with our client-side converter.

Open cURL Converter