Hammer Meet Nail
Ctrl+K

HTTP Status Codes

What each status code means, who sends it, and when

1xx · Informational

An interim word while the server still works on the request — nothing final yet, and safe to ignore.

CodePhraseMeaningSource
100ContinueThe server has seen the headers and the client should go ahead and send the body it asked permission for.RFC 9110
101Switching ProtocolsThe server agrees to the client’s Upgrade — WebSocket, most often — and switches protocols on this connection.RFC 9110
102ProcessingobsoleteWebDAV’s interim “still working” signal; dropped when RFC 4918 revised WebDAV, and no longer sent.RFC 2518
103Early HintsLikely headers — preload links, mostly — sent before the final response so the client can start fetching early.RFC 8297

2xx · Success

The request was received, understood, and acted on as asked.

CodePhraseMeaningSource
200OKThe request succeeded, and the answer — page, data, result — is in the response.RFC 9110
201CreatedThe request created a resource, typically named by the Location header; the usual answer to a creating POST or PUT.RFC 9110
202AcceptedThe server took the request for later processing and promises nothing about the outcome.RFC 9110
203Non-Authoritative InformationThe request succeeded but a transforming proxy altered the response on the way — it is not the origin’s exact answer.RFC 9110
204No ContentSuccess with nothing to send back — the usual answer to a DELETE or a save that returns nothing.RFC 9110
205Reset ContentSuccess, and the server asks the client to reset the view that produced the request — clear the form.RFC 9110
206Partial ContentThe response carries only the byte range the client asked for — resumed downloads and video seeking.RFC 9110
207Multi-StatusWebDAV’s envelope for several sub-responses at once, each resource with its own status inside the body.RFC 4918
208Already ReportedWebDAV: this member was already listed earlier in the multi-status answer, so its details are not repeated.RFC 5842
226IM UsedThe response is a delta against what the client already holds rather than the full resource; rarely deployed.RFC 3229

3xx · Redirection

The resource is elsewhere or unchanged — the client has another step to take, usually following a new address.

CodePhraseMeaningSource
300Multiple ChoicesMore than one representation fits, and the client is offered the list to choose from; rare in the wild.RFC 9110
301Moved PermanentlyThe resource lives at the address in Location for good — update links; a redirected POST may be replayed as GET.RFC 9110
302FoundA temporary redirect; browsers historically follow it with GET regardless of method, which is why 307 exists.RFC 9110
303See OtherThe answer lives at another address the client should GET — the classic redirect after a form POST.RFC 9110
304Not ModifiedThe client’s cached copy is still good — sent in answer to a conditional request, with no body.RFC 9110
305Use ProxyobsoleteOnce told clients to repeat the request through a proxy; deprecated for security and no longer used.RFC 9110
306(Unused)reservedWas “Switch Proxy” in a draft; retired, and the number is held unused.RFC 9110
307Temporary RedirectA temporary redirect that keeps the method — a POST stays a POST at the new address.RFC 9110
308Permanent RedirectA permanent redirect that keeps the method — 301’s promise without the POST-to-GET rewrite.RFC 9110

4xx · Client error

The request itself is at fault — malformed, unauthorized, or aimed at something that is not there. Repeating it unchanged will fail again.

CodePhraseMeaningSource
400Bad RequestThe server cannot or will not process the request as sent — malformed syntax, bad framing, or plain nonsense.RFC 9110
401UnauthorizedThe request lacks valid credentials; WWW-Authenticate says how to present them. Despite the name, this is authentication.RFC 9110
402Payment RequiredreservedReserved since HTTP/1.1 for a payment scheme that never arrived; a few APIs use it for billing limits anyway.RFC 9110
403ForbiddenThe server understood and refuses: the identity presented, valid or not, does not grant access to this resource.RFC 9110
404Not FoundNothing lives at this address — or the server prefers not to say that something does.RFC 9110
405Method Not AllowedThe address exists but not for this method — a POST where only GET is served; Allow lists what is.RFC 9110
406Not AcceptableThe server has no representation matching what the request’s Accept headers will take.RFC 9110
407Proxy Authentication Required401’s twin from an intermediary: the proxy wants credentials before it will forward the request.RFC 9110
408Request TimeoutThe server gave up waiting for the rest of the request and closed the exchange; the client may retry.RFC 9110
409ConflictThe request conflicts with the resource’s current state — an edit over someone else’s newer version, a name already taken.RFC 9110
410GoneThe resource existed and was removed on purpose, with no forwarding address — a deliberate, permanent 404.RFC 9110
411Length RequiredThe server insists on a Content-Length header before it will accept the request body.RFC 9110
412Precondition FailedA condition the client attached — If-Match, usually — is not true, so the server did not act; the guard of optimistic concurrency.RFC 9110
413Content Too LargeThe request body is bigger than the server will process — upload limits, most often.RFC 9110
414URI Too LongThe request’s address itself is longer than the server will read — usually a query string that grew out of hand.RFC 9110
415Unsupported Media TypeThe body’s format is one the server does not take for this resource — XML where JSON was expected.RFC 9110
416Range Not SatisfiableThe requested byte range lies outside the resource — asking past the end of the file.RFC 9110
417Expectation FailedThe request’s Expect header asks for something the server cannot promise.RFC 9110
418I’m a TeapotreservedAn April Fools joke — HTCPCP’s answer from a teapot asked to brew coffee. HTTP holds the number reserved, and real servers send it only in jest.RFC 2324RFC 9110
421Misdirected RequestThe request reached a server not configured to answer for that authority — a connection reused for the wrong host.RFC 9110
422Unprocessable ContentThe body parses but its meaning does not work — well-formed JSON failing validation is the classic; a syntax fault is 400’s.RFC 9110
423LockedWebDAV: the resource is locked by someone else, so the change cannot be made.RFC 4918
424Failed DependencyWebDAV: this action failed because an earlier action it depended on failed.RFC 4918
425Too EarlyThe server will not risk processing a request replayed from TLS early data; retry once the handshake completes.RFC 8470
426Upgrade RequiredThe server refuses to serve this protocol version — the Upgrade header names what to switch to first.RFC 9110
428Precondition RequiredThe server insists the request carry a condition — send If-Match, so a blind write cannot trample someone else’s.RFC 6585
429Too Many RequestsThe client has sent too much too fast and is being rate-limited; Retry-After, when present, says how long to wait.RFC 6585
431Request Header Fields Too LargeThe request’s headers — one, or all together — are bigger than the server will read; often a runaway cookie.RFC 6585
444No Responseunregisterednginx’s internal marker for closing the connection without answering — seen in logs, never on the wire as a response.nginx
451Unavailable For Legal ReasonsThe server is legally barred from serving the resource — censorship or court order, named after Bradbury.RFC 7725
499Client Closed Requestunregisterednginx’s log entry for a client that hung up before the response was ready; nothing was sent.nginx

5xx · Server error

The server failed to do what a well-formed request asked — the fault is on its side, and retrying later may succeed.

CodePhraseMeaningSource
500Internal Server ErrorSomething broke on the server while handling the request — the generic “not the client’s fault”.RFC 9110
501Not ImplementedThe server does not support the request method at all — anywhere, unlike 405’s per-resource refusal.RFC 9110
502Bad GatewayA gateway or proxy got an invalid response from the upstream server it asked on the client’s behalf.RFC 9110
503Service UnavailableThe server is temporarily unable to serve — overloaded or down for maintenance; Retry-After, when present, says when to come back.RFC 9110
504Gateway TimeoutA gateway or proxy gave up waiting for the upstream server to answer.RFC 9110
505HTTP Version Not SupportedThe server refuses the request’s major HTTP version.RFC 9110
506Variant Also NegotiatesA content-negotiation misconfiguration: the chosen variant negotiates in turn; experimental and rarely seen.RFC 2295
507Insufficient StorageWebDAV: the server cannot store what completing the request would need.RFC 4918
508Loop DetectedWebDAV: the server hit an infinite loop — a binding that contains itself — while processing the request.RFC 5842
510Not ExtendedobsoleteAsked for an HTTP extension the server does not hold; RFC 2774 is historic and the code is effectively dead.RFC 2774
511Network Authentication RequiredSent by a captive portal — hotel or airport Wi-Fi — that wants a login before it will pass traffic; not from the origin server.RFC 6585
520Web Server Returned an Unknown ErrorunregisteredCloudflare’s catch-all for an origin answer it cannot interpret — empty, malformed, or an unexpected protocol.Cloudflare
521Web Server Is DownunregisteredCloudflare reached out to the origin and the connection was refused.Cloudflare
522Connection Timed OutunregisteredCloudflare could not complete a TCP connection to the origin in time.Cloudflare
523Origin Is UnreachableunregisteredCloudflare cannot route to the origin at all — DNS or network, not a refusal.Cloudflare
524A Timeout OccurredunregisteredThe origin accepted the connection but did not answer within Cloudflare’s time limit.Cloudflare
525SSL Handshake FailedunregisteredThe TLS handshake between Cloudflare and the origin failed.Cloudflare
526Invalid SSL CertificateunregisteredCloudflare rejected the origin’s TLS certificate — expired, self-signed, or the wrong name.Cloudflare
527Railgun ErrorunregisteredA failure in Cloudflare’s retired Railgun accelerator; historical — the product is gone, the code lingers in old logs.Cloudflare

Codes and phrases as the IANA HTTP Status Code Registry records them; each row names its defining document. Rows marked unregistered are widely deployed but registered by no one.