HTTP Status Codes
What each status code means, who sends it, and when
1xx · Informational
An interim word while the server still works on the request — nothing final yet, and safe to ignore.
| Code | Phrase | Meaning | Source |
|---|---|---|---|
| 100 | Continue | The server has seen the headers and the client should go ahead and send the body it asked permission for. | RFC 9110 |
| 101 | Switching Protocols | The server agrees to the client’s Upgrade — WebSocket, most often — and switches protocols on this connection. | RFC 9110 |
| 102 | Processing | obsoleteWebDAV’s interim “still working” signal; dropped when RFC 4918 revised WebDAV, and no longer sent. | RFC 2518 |
| 103 | Early Hints | Likely headers — preload links, mostly — sent before the final response so the client can start fetching early. | RFC 8297 |
2xx · Success
The request was received, understood, and acted on as asked.
| Code | Phrase | Meaning | Source |
|---|---|---|---|
| 200 | OK | The request succeeded, and the answer — page, data, result — is in the response. | RFC 9110 |
| 201 | Created | The request created a resource, typically named by the Location header; the usual answer to a creating POST or PUT. | RFC 9110 |
| 202 | Accepted | The server took the request for later processing and promises nothing about the outcome. | RFC 9110 |
| 203 | Non-Authoritative Information | The request succeeded but a transforming proxy altered the response on the way — it is not the origin’s exact answer. | RFC 9110 |
| 204 | No Content | Success with nothing to send back — the usual answer to a DELETE or a save that returns nothing. | RFC 9110 |
| 205 | Reset Content | Success, and the server asks the client to reset the view that produced the request — clear the form. | RFC 9110 |
| 206 | Partial Content | The response carries only the byte range the client asked for — resumed downloads and video seeking. | RFC 9110 |
| 207 | Multi-Status | WebDAV’s envelope for several sub-responses at once, each resource with its own status inside the body. | RFC 4918 |
| 208 | Already Reported | WebDAV: this member was already listed earlier in the multi-status answer, so its details are not repeated. | RFC 5842 |
| 226 | IM Used | The response is a delta against what the client already holds rather than the full resource; rarely deployed. | RFC 3229 |
3xx · Redirection
The resource is elsewhere or unchanged — the client has another step to take, usually following a new address.
| Code | Phrase | Meaning | Source |
|---|---|---|---|
| 300 | Multiple Choices | More than one representation fits, and the client is offered the list to choose from; rare in the wild. | RFC 9110 |
| 301 | Moved Permanently | The resource lives at the address in Location for good — update links; a redirected POST may be replayed as GET. | RFC 9110 |
| 302 | Found | A temporary redirect; browsers historically follow it with GET regardless of method, which is why 307 exists. | RFC 9110 |
| 303 | See Other | The answer lives at another address the client should GET — the classic redirect after a form POST. | RFC 9110 |
| 304 | Not Modified | The client’s cached copy is still good — sent in answer to a conditional request, with no body. | RFC 9110 |
| 305 | Use Proxy | obsoleteOnce told clients to repeat the request through a proxy; deprecated for security and no longer used. | RFC 9110 |
| 306 | (Unused) | reservedWas “Switch Proxy” in a draft; retired, and the number is held unused. | RFC 9110 |
| 307 | Temporary Redirect | A temporary redirect that keeps the method — a POST stays a POST at the new address. | RFC 9110 |
| 308 | Permanent Redirect | A permanent redirect that keeps the method — 301’s promise without the POST-to-GET rewrite. | RFC 9110 |
4xx · Client error
The request itself is at fault — malformed, unauthorized, or aimed at something that is not there. Repeating it unchanged will fail again.
| Code | Phrase | Meaning | Source |
|---|---|---|---|
| 400 | Bad Request | The server cannot or will not process the request as sent — malformed syntax, bad framing, or plain nonsense. | RFC 9110 |
| 401 | Unauthorized | The request lacks valid credentials; WWW-Authenticate says how to present them. Despite the name, this is authentication. | RFC 9110 |
| 402 | Payment Required | reservedReserved since HTTP/1.1 for a payment scheme that never arrived; a few APIs use it for billing limits anyway. | RFC 9110 |
| 403 | Forbidden | The server understood and refuses: the identity presented, valid or not, does not grant access to this resource. | RFC 9110 |
| 404 | Not Found | Nothing lives at this address — or the server prefers not to say that something does. | RFC 9110 |
| 405 | Method Not Allowed | The address exists but not for this method — a POST where only GET is served; Allow lists what is. | RFC 9110 |
| 406 | Not Acceptable | The server has no representation matching what the request’s Accept headers will take. | RFC 9110 |
| 407 | Proxy Authentication Required | 401’s twin from an intermediary: the proxy wants credentials before it will forward the request. | RFC 9110 |
| 408 | Request Timeout | The server gave up waiting for the rest of the request and closed the exchange; the client may retry. | RFC 9110 |
| 409 | Conflict | The request conflicts with the resource’s current state — an edit over someone else’s newer version, a name already taken. | RFC 9110 |
| 410 | Gone | The resource existed and was removed on purpose, with no forwarding address — a deliberate, permanent 404. | RFC 9110 |
| 411 | Length Required | The server insists on a Content-Length header before it will accept the request body. | RFC 9110 |
| 412 | Precondition Failed | A condition the client attached — If-Match, usually — is not true, so the server did not act; the guard of optimistic concurrency. | RFC 9110 |
| 413 | Content Too Large | The request body is bigger than the server will process — upload limits, most often. | RFC 9110 |
| 414 | URI Too Long | The request’s address itself is longer than the server will read — usually a query string that grew out of hand. | RFC 9110 |
| 415 | Unsupported Media Type | The body’s format is one the server does not take for this resource — XML where JSON was expected. | RFC 9110 |
| 416 | Range Not Satisfiable | The requested byte range lies outside the resource — asking past the end of the file. | RFC 9110 |
| 417 | Expectation Failed | The request’s Expect header asks for something the server cannot promise. | RFC 9110 |
| 418 | I’m a Teapot | reservedAn April Fools joke — HTCPCP’s answer from a teapot asked to brew coffee. HTTP holds the number reserved, and real servers send it only in jest. | RFC 2324RFC 9110 |
| 421 | Misdirected Request | The request reached a server not configured to answer for that authority — a connection reused for the wrong host. | RFC 9110 |
| 422 | Unprocessable Content | The body parses but its meaning does not work — well-formed JSON failing validation is the classic; a syntax fault is 400’s. | RFC 9110 |
| 423 | Locked | WebDAV: the resource is locked by someone else, so the change cannot be made. | RFC 4918 |
| 424 | Failed Dependency | WebDAV: this action failed because an earlier action it depended on failed. | RFC 4918 |
| 425 | Too Early | The server will not risk processing a request replayed from TLS early data; retry once the handshake completes. | RFC 8470 |
| 426 | Upgrade Required | The server refuses to serve this protocol version — the Upgrade header names what to switch to first. | RFC 9110 |
| 428 | Precondition Required | The server insists the request carry a condition — send If-Match, so a blind write cannot trample someone else’s. | RFC 6585 |
| 429 | Too Many Requests | The client has sent too much too fast and is being rate-limited; Retry-After, when present, says how long to wait. | RFC 6585 |
| 431 | Request Header Fields Too Large | The request’s headers — one, or all together — are bigger than the server will read; often a runaway cookie. | RFC 6585 |
| 444 | No Response | unregisterednginx’s internal marker for closing the connection without answering — seen in logs, never on the wire as a response. | nginx |
| 451 | Unavailable For Legal Reasons | The server is legally barred from serving the resource — censorship or court order, named after Bradbury. | RFC 7725 |
| 499 | Client Closed Request | unregisterednginx’s log entry for a client that hung up before the response was ready; nothing was sent. | nginx |
5xx · Server error
The server failed to do what a well-formed request asked — the fault is on its side, and retrying later may succeed.
| Code | Phrase | Meaning | Source |
|---|---|---|---|
| 500 | Internal Server Error | Something broke on the server while handling the request — the generic “not the client’s fault”. | RFC 9110 |
| 501 | Not Implemented | The server does not support the request method at all — anywhere, unlike 405’s per-resource refusal. | RFC 9110 |
| 502 | Bad Gateway | A gateway or proxy got an invalid response from the upstream server it asked on the client’s behalf. | RFC 9110 |
| 503 | Service Unavailable | The server is temporarily unable to serve — overloaded or down for maintenance; Retry-After, when present, says when to come back. | RFC 9110 |
| 504 | Gateway Timeout | A gateway or proxy gave up waiting for the upstream server to answer. | RFC 9110 |
| 505 | HTTP Version Not Supported | The server refuses the request’s major HTTP version. | RFC 9110 |
| 506 | Variant Also Negotiates | A content-negotiation misconfiguration: the chosen variant negotiates in turn; experimental and rarely seen. | RFC 2295 |
| 507 | Insufficient Storage | WebDAV: the server cannot store what completing the request would need. | RFC 4918 |
| 508 | Loop Detected | WebDAV: the server hit an infinite loop — a binding that contains itself — while processing the request. | RFC 5842 |
| 510 | Not Extended | obsoleteAsked for an HTTP extension the server does not hold; RFC 2774 is historic and the code is effectively dead. | RFC 2774 |
| 511 | Network Authentication Required | Sent by a captive portal — hotel or airport Wi-Fi — that wants a login before it will pass traffic; not from the origin server. | RFC 6585 |
| 520 | Web Server Returned an Unknown Error | unregisteredCloudflare’s catch-all for an origin answer it cannot interpret — empty, malformed, or an unexpected protocol. | Cloudflare |
| 521 | Web Server Is Down | unregisteredCloudflare reached out to the origin and the connection was refused. | Cloudflare |
| 522 | Connection Timed Out | unregisteredCloudflare could not complete a TCP connection to the origin in time. | Cloudflare |
| 523 | Origin Is Unreachable | unregisteredCloudflare cannot route to the origin at all — DNS or network, not a refusal. | Cloudflare |
| 524 | A Timeout Occurred | unregisteredThe origin accepted the connection but did not answer within Cloudflare’s time limit. | Cloudflare |
| 525 | SSL Handshake Failed | unregisteredThe TLS handshake between Cloudflare and the origin failed. | Cloudflare |
| 526 | Invalid SSL Certificate | unregisteredCloudflare rejected the origin’s TLS certificate — expired, self-signed, or the wrong name. | Cloudflare |
| 527 | Railgun Error | unregisteredA failure in Cloudflare’s retired Railgun accelerator; historical — the product is gone, the code lingers in old logs. | Cloudflare |
Codes and phrases as the IANA HTTP Status Code Registry records them; each row names its defining document. Rows marked unregistered are widely deployed but registered by no one.