InformationEducationUtilityDeveloper

HTTP Status Code Reference

HTTP status code reference with searchable definitions and practical use cases for 1xx informational, 2xx success, 3xx redirection, 4xx client error, and 5xx server error.

Total

48

1xx

4

2xx

5

3xx

7

4xx

22

5xx

10

CodeTitleClassDescriptionTypical use
1xx Informational · 100~103
100Continue1xx InformationalRequest headers received, continue sending body.Large upload handshakes
101Switching Protocols1xx InformationalServer is switching protocols as requested.WebSocket upgrade
102Processing1xx InformationalServer accepted but is still processing.Long-running WebDAV operations
103Early Hints1xx InformationalPreliminary response with link hints.Preload assets early
2xx Success · 200~206
200OK2xx SuccessRequest succeeded.Standard API or page response
201Created2xx SuccessResource created successfully.POST create endpoints
202Accepted2xx SuccessAccepted for async processing.Queue-based workflows
204No Content2xx SuccessSuccess with no response body.DELETE or idempotent updates
206Partial Content2xx SuccessPartial range response.Media streaming and resume download
3xx Redirection · 300~308
300Multiple Choices3xx RedirectionMultiple representations available.Variant negotiation
301Moved Permanently3xx RedirectionPermanent redirect to new URL.Canonical URL migration
302Found3xx RedirectionTemporary redirect.Short-lived relocation
303See Other3xx RedirectionRedirect to retrieval endpoint.Post/Redirect/Get pattern
304Not Modified3xx RedirectionCached version is still valid.Conditional requests with ETag
307Temporary Redirect3xx RedirectionTemporary redirect preserving method.Safe temporary reroute
308Permanent Redirect3xx RedirectionPermanent redirect preserving method.Strict migration of APIs
4xx Client Error · 400~451
400Bad Request4xx Client ErrorInvalid request syntax or payload.Schema validation failures
401Unauthorized4xx Client ErrorAuthentication required or invalid.Missing/invalid token
403Forbidden4xx Client ErrorAuthenticated but not allowed.Role or policy denial
404Not Found4xx Client ErrorResource not found.Unknown route or identifier
405Method Not Allowed4xx Client ErrorHTTP method not supported.Wrong verb on endpoint
406Not Acceptable4xx Client ErrorNo acceptable representation available.Content negotiation mismatch
408Request Timeout4xx Client ErrorClient took too long.Idle client connection
409Conflict4xx Client ErrorRequest conflicts with current state.Versioning or duplicate conflict
410Gone4xx Client ErrorResource permanently removed.Intentional endpoint retirement
412Precondition Failed4xx Client ErrorConditional header precondition failed.If-Match mismatch
413Payload Too Large4xx Client ErrorRequest body exceeds limit.Upload size enforcement
414URI Too Long4xx Client ErrorRequest URI is too long.Oversized query string
415Unsupported Media Type4xx Client ErrorContent type not supported.Invalid upload media type
418I'm a teapot4xx Client ErrorRFC joke code, rarely used in prod.Debug/easter egg responses
421Misdirected Request4xx Client ErrorRequest sent to wrong server.HTTP/2 authority mismatch
422Unprocessable Content4xx Client ErrorWell-formed but semantic errors.Business rule validation errors
425Too Early4xx Client ErrorServer unwilling to risk replay.Early data replay protection
426Upgrade Required4xx Client ErrorClient must switch protocol.Require TLS or newer protocol
428Precondition Required4xx Client ErrorServer requires conditional request.Lost-update prevention
429Too Many Requests4xx Client ErrorRate limit exceeded.Throttle abusive traffic
431Request Header Fields Too Large4xx Client ErrorHeaders exceed acceptable size.Oversized cookies/headers
451Unavailable For Legal Reasons4xx Client ErrorBlocked by legal requirement.Compliance takedown restrictions
5xx Server Error · 500~511
500Internal Server Error5xx Server ErrorUnexpected server-side failure.Unhandled exceptions
501Not Implemented5xx Server ErrorFeature not implemented.Unsupported endpoint capability
502Bad Gateway5xx Server ErrorInvalid response from upstream.Proxy or gateway upstream errors
503Service Unavailable5xx Server ErrorService temporarily unavailable.Maintenance or overload
504Gateway Timeout5xx Server ErrorUpstream timed out.Dependency timeout propagation
505HTTP Version Not Supported5xx Server ErrorHTTP version not supported.Legacy protocol rejection
507Insufficient Storage5xx Server ErrorServer cannot store representation.Storage quota exhaustion
508Loop Detected5xx Server ErrorInfinite loop detected during processing.Recursive WebDAV operations
510Not Extended5xx Server ErrorFurther extensions required.Extension policy requirements
511Network Authentication Required5xx Server ErrorNetwork authentication required.Captive portal environments

What is HTTP?

HTTP (Hypertext Transfer Protocol) is the request-response protocol used by browsers, mobile apps, and APIs to communicate with web servers.

A client sends a request (method, URL, headers, body), and the server returns a response (status code, headers, body). The status code is the first signal that tells clients whether the request succeeded, failed, or should be redirected.

In production systems, correct status codes improve caching, retry logic, monitoring, SEO behavior, and developer debugging speed.

How to read HTTP status code classes

1xx · Informational

Request received, processing continues.

2xx · Success

Request completed successfully.

3xx · Redirection

Client should perform another request to a different URL.

4xx · Client Error

Request is invalid or unauthorized from client side.

5xx · Server Error

Server failed to process a valid request.

Response examples by code

200 OK (JSON API)

HTTP/1.1 200 OK
Content-Type: application/json

{
  "id": "user_123",
  "name": "Alex",
  "email": "[email protected]"
}

404 Not Found

HTTP/1.1 404 Not Found
Content-Type: application/json

{
  "error": "RESOURCE_NOT_FOUND",
  "message": "User does not exist."
}

429 Too Many Requests

HTTP/1.1 429 Too Many Requests
Retry-After: 60
Content-Type: application/json

{
  "error": "RATE_LIMITED",
  "message": "Try again after 60 seconds."
}

Common implementation mistakes

Returning 200 for every API response hides failures from clients. Use semantically correct status codes so retries, alerts, and analytics behave correctly.

Confusing 401 and 403 is another common issue. Use 401 for authentication failures and 403 for authorization denial after identity is known.

Use 429 for rate limiting and include backoff hints where possible. Avoid masking upstream gateway failures (502/504) as generic 500 errors.