Skip to content

HTTP Status Codes

Every standard status code, what it means and where it's defined.

About HTTP status codes

An HTTP status code is the three-digit number at the start of every response that tells the client how the request went. The first digit sets the class: 1xx informational, 2xx success, 3xx redirection, 4xx client error and 5xx server error. Clients that don't recognise a specific code treat it like the x00 code of its class, so an unknown 4xx is handled as 400.

This list covers every code in the IANA HTTP Status Code Registry except temporary registrations, with names as RFC 9110 (HTTP Semantics, 2022) gives them. Some names changed in RFC 9110: 413 is now Content Too Large (formerly Payload Too Large) and 422 is Unprocessable Content (formerly Unprocessable Entity). Codes that come from extensions such as WebDAV note the RFC that defines them.

63 entries

1xx Informational

Interim responses: the request was received and processing continues.

CodeNameMeaningDefined in
100ContinueThe request headers were received; the client should send the body (used with Expect: 100-continue).RFC 9110
101Switching ProtocolsThe server is switching to the protocol named in the Upgrade header, for example WebSocket.RFC 9110
102ProcessingWebDAV: the server has accepted the request but hasn't finished it yet.RFC 2518
103Early HintsSends Link headers early so the browser can preload resources while the final response is prepared.RFC 8297

2xx Success

The request was received, understood and accepted.

CodeNameMeaningDefined in
200OKThe request succeeded. The body depends on the method: the resource for GET, the result for POST.RFC 9110
201CreatedThe request created a new resource, usually identified by the Location header.RFC 9110
202AcceptedThe request was accepted for processing, which hasn't finished (and may still fail).RFC 9110
203Non-Authoritative InformationSuccess, but a proxy changed the payload from the origin server's response.RFC 9110
204No ContentSuccess with no response body, common for DELETE and for PUT that returns nothing.RFC 9110
205Reset ContentSuccess; the client should reset the document view, such as clearing a form.RFC 9110
206Partial ContentReturns only the byte range asked for in the Range header, used for resumable downloads and video.RFC 9110
207Multi-StatusWebDAV: the body holds separate status codes for several resources.RFC 4918
208Already ReportedWebDAV: members of a binding were already listed earlier in the same response.RFC 5842
226IM UsedThe response is the result of instance manipulations (delta encoding) applied to the resource.RFC 3229

3xx Redirection

The client must take another step, usually following the Location header.

CodeNameMeaningDefined in
300Multiple ChoicesThe resource has several representations and the client may choose one.RFC 9110
301Moved PermanentlyThe resource has a new permanent URL in Location. Clients may change POST to GET when following it.RFC 9110
302FoundTemporary redirect to Location. Clients may change POST to GET when following it.RFC 9110
303See OtherRedirect to another resource with GET, for example after a form POST (Post/Redirect/Get).RFC 9110
304Not ModifiedThe cached copy is still valid (after If-None-Match or If-Modified-Since); no body is sent.RFC 9110
305Use ProxyDeprecated: asked the client to use a proxy. Not supported by browsers for security reasons.RFC 9110
306(Unused)Used in an earlier draft and now reserved.RFC 9110
307Temporary RedirectTemporary redirect that keeps the method and body, so a POST stays a POST.RFC 9110
308Permanent RedirectPermanent redirect that keeps the method and body.RFC 9110

4xx Client errors

The request has a problem the client should fix before retrying.

CodeNameMeaningDefined in
400Bad RequestThe server can't process the request because of a client error, such as malformed syntax.RFC 9110
401UnauthorizedAuthentication is missing or invalid. The response includes a WWW-Authenticate header.RFC 9110
402Payment RequiredReserved for future use; some APIs use it for billing errors.RFC 9110
403ForbiddenThe server understood the request but refuses it; authenticating won't help.RFC 9110
404Not FoundNo resource exists at this URL, or the server won't reveal that it does.RFC 9110
405Method Not AllowedThe method isn't supported for this resource. The Allow header lists those that are.RFC 9110
406Not AcceptableNo representation matches the request's Accept headers.RFC 9110
407Proxy Authentication RequiredLike 401, but the client must authenticate with a proxy.RFC 9110
408Request TimeoutThe server timed out waiting for the request to finish.RFC 9110
409ConflictThe request conflicts with the current state of the resource, such as an edit conflict.RFC 9110
410GoneThe resource was removed permanently and won't come back.RFC 9110
411Length RequiredThe server requires a Content-Length header.RFC 9110
412Precondition FailedA condition in the request headers, such as If-Match, was false.RFC 9110
413Content Too LargeThe request body is larger than the server will accept (formerly Payload Too Large).RFC 9110
414URI Too LongThe request URL is longer than the server will process.RFC 9110
415Unsupported Media TypeThe request body's format (Content-Type or Content-Encoding) isn't supported.RFC 9110
416Range Not SatisfiableThe requested Range lies outside the resource.RFC 9110
417Expectation FailedThe server can't meet the request's Expect header.RFC 9110
418(Unused)Reserved. Known as "I'm a teapot" from the 1998 April Fools' RFC 2324; not a real status.RFC 9110
421Misdirected RequestThe request reached a server that can't produce a response for this host and scheme.RFC 9110
422Unprocessable ContentThe syntax is valid but the content can't be processed, such as failed validation.RFC 9110
423LockedWebDAV: the resource is locked.RFC 4918
424Failed DependencyWebDAV: the request failed because a request it depended on failed.RFC 4918
425Too EarlyThe server won't risk processing a request that might be replayed (TLS early data).RFC 8470
426Upgrade RequiredThe client must switch to a different protocol, named in the Upgrade header.RFC 9110
428Precondition RequiredThe server requires a conditional request, such as If-Match, to prevent lost updates.RFC 6585
429Too Many RequestsRate limit reached. A Retry-After header may say when to try again.RFC 6585
431Request Header Fields Too LargeOne header, or all headers together, are too large (often oversized cookies).RFC 6585
451Unavailable For Legal ReasonsAccess is denied because of a legal demand, such as a court order.RFC 7725

5xx Server errors

The server failed to fulfil a request that may well be valid.

CodeNameMeaningDefined in
500Internal Server ErrorThe server hit an unexpected condition. Check the server logs.RFC 9110
501Not ImplementedThe server doesn't support the functionality the request needs, such as an unknown method.RFC 9110
502Bad GatewayA gateway or proxy got an invalid response from the upstream server.RFC 9110
503Service UnavailableThe server is overloaded or down for maintenance. Retry-After may say when it'll be back.RFC 9110
504Gateway TimeoutA gateway or proxy didn't get a response from the upstream server in time.RFC 9110
505HTTP Version Not SupportedThe server doesn't support the HTTP version of the request.RFC 9110
506Variant Also NegotiatesContent negotiation is misconfigured: the chosen variant negotiates too.RFC 2295
507Insufficient StorageWebDAV: the server can't store what's needed to complete the request.RFC 4918
508Loop DetectedWebDAV: the server found an infinite loop while processing the request.RFC 5842
510Not ExtendedFurther extensions are required (RFC 2774, now historic).RFC 2774
511Network Authentication RequiredThe client must authenticate to get network access, as with a captive Wi-Fi portal.RFC 6585

Good to know

401 or 403?

401 Unauthorized means the request has no valid credentials: log in and try again. 403 Forbidden means the server knows who you are (or doesn't need to) and still refuses: logging in again won't help.

301, 302, 307 or 308?

Use 301 or 308 for permanent moves and 302 or 307 for temporary ones. 307 and 308 guarantee that the method and body are kept, so a POST stays a POST; with 301 and 302 clients may switch to GET. Search engines treat 301 and 308 as permanent signals.

502, 503 or 504?

All three often come from a proxy or load balancer. 502 means the upstream server sent an invalid response or none (often it crashed), 503 means the service is unavailable or overloaded, and 504 means the upstream server took too long.

More references