HTTP Status Codes Table
| Code | Name | What it means |
|---|---|---|
| 100 | Continue | The client should continue with the request - an interim response while the server reads the body. |
| 101 | Switching Protocols | The server agrees to switch protocols, e.g. to WebSocket via the Upgrade header. |
| 200 | OK | The standard success response - the request worked and the payload follows. |
| 201 | Created | Success plus a new resource - the response usually points at it via Location. |
| 204 | No Content | Success with an empty body - the workhorse of save-and-stay-quiet actions. |
| 206 | Partial Content | Range requests served - the reason paused video downloads resume instead of restarting. |
| 301 | Moved Permanently | The resource lives somewhere else forever - browsers and search engines update their links. |
| 302 | Found | A temporary redirect - the original URL stays the canonical one. |
| 304 | Not Modified | The cached copy is still valid - the cache negotiation workhorse that saves the bandwidth. |
| 307 | Temporary Redirect | Like 302 but the request method and body may not change. |
| 308 | Permanent Redirect | Like 301 but the request method and body may not change. |
| 400 | Bad Request | The server cannot process the malformed request - often a broken JSON body or bad encoding. |
| 401 | Unauthorized | Actually means unauthenticated: who are you? Log in first. |
| 403 | Forbidden | The server knows who you are and still refuses - permissions, IP bans, geo rules. |
| 404 | Not Found | The most famous error: no resource at this URL. Also the soft-failure a SPA shows when its route misses. |
| 405 | Method Not Allowed | DELETE on an endpoint that only accepts POST - the method exists, the verb is wrong. |
| 409 | Conflict | The request clashes with the current state - edit collisions, duplicate registrations. |
| 410 | Gone | Like 404 but deliberate: the resource was removed and is not coming back. |
| 413 | Payload Too Large | The body exceeds what the server accepts - classic with big uploads behind a proxy limit. |
| 415 | Unsupported Media Type | The Content-Type is not something this endpoint parses. |
| 418 | I’m a teapot | An April Fools RFC 2324 joke, now formally reserved - some servers still brew. |
| 422 | Unprocessable Content | Syntactically valid, semantically wrong - the validation-error favorite of modern APIs. |
| 429 | Too Many Requests | Rate limiting hit - servers usually attach a Retry-After header saying when to come back. |
| 451 | Unavailable For Legal Reasons | Censored by law - GDPR takedowns and national blocks identify themselves. |
| 500 | Internal Server Error | A generic server-side crash - the bug is in the server, not your request. |
| 502 | Bad Gateway | An upstream server returned garbage - the proxy between you and the app is reporting the failure. |
| 503 | Service Unavailable | Overloaded or down for maintenance - often temporary, often with a Retry-After. |
| 504 | Gateway Timeout | The upstream server did not answer in time - the proxy gave up waiting. |
The HTTP status code registry holds sixty-plus codes, but server logs live on about twenty-eight of them - and the errors people actually debug cluster in a dozen. This table carries the working set verbatim from MDN, filterable by code, class, or the symptom you are staring at.
The table is honest about the pairs everyone confuses: 401 means who are you while 403 means I know who you are and no; 301 and 308 are both permanent, differing only in whether the HTTP method survives the trip.
How to use
- Type a code (418), a name (redirect), or a symptom (timeout) - the table filters live.
- Click any code cell to copy it for an incident ticket or a bug report.
- Class chips jump to the 4xx client-error and 5xx server-error families - the two sides of every outage argument.
Frequently asked questions
What is the difference between 301, 302, 307 and 308?
Permanent vs temporary, and method preservation: 301 and 302 are the classics but let clients switch POST to GET; 307 and 308 are the strict versions that guarantee the method and body survive. Rule of thumb - moved APIs use 308, moved marketing pages use 301, everything temporary uses 307.
Why does my single-page app return 200 on a missing page?
The server delivers the app shell with 200 and the router decides afterward - a soft 404. Crawlers read the status line, see success, and index the nothing. Real fixes return a genuine 404 status from the server or render it client-side with a meta noindex.
When should I return 410 instead of 404?
When the removal is deliberate and permanent: 410 Gone tells crawlers to drop the URL faster and never re-check, while 404 leaves the URL in limbo. Content you deleted on purpose deserves 410; typos and private URLs stay 404.
What is 418 I’m a teapot?
An April Fools joke from the 1998 HTCPCP protocol (Hyper Text Coffee Pot Control Protocol) that became a beloved easter egg. The IETF reserved it officially in 2018 - it should never be sent, but some APIs return it on April 1 anyway.