HTTP Status Codes Table

–28 codes - the ones that actually appear in logs
CodeNameWhat it means
100ContinueThe client should continue with the request - an interim response while the server reads the body.
101Switching ProtocolsThe server agrees to switch protocols, e.g. to WebSocket via the Upgrade header.
200OKThe standard success response - the request worked and the payload follows.
201CreatedSuccess plus a new resource - the response usually points at it via Location.
204No ContentSuccess with an empty body - the workhorse of save-and-stay-quiet actions.
206Partial ContentRange requests served - the reason paused video downloads resume instead of restarting.
301Moved PermanentlyThe resource lives somewhere else forever - browsers and search engines update their links.
302FoundA temporary redirect - the original URL stays the canonical one.
304Not ModifiedThe cached copy is still valid - the cache negotiation workhorse that saves the bandwidth.
307Temporary RedirectLike 302 but the request method and body may not change.
308Permanent RedirectLike 301 but the request method and body may not change.
400Bad RequestThe server cannot process the malformed request - often a broken JSON body or bad encoding.
401UnauthorizedActually means unauthenticated: who are you? Log in first.
403ForbiddenThe server knows who you are and still refuses - permissions, IP bans, geo rules.
404Not FoundThe most famous error: no resource at this URL. Also the soft-failure a SPA shows when its route misses.
405Method Not AllowedDELETE on an endpoint that only accepts POST - the method exists, the verb is wrong.
409ConflictThe request clashes with the current state - edit collisions, duplicate registrations.
410GoneLike 404 but deliberate: the resource was removed and is not coming back.
413Payload Too LargeThe body exceeds what the server accepts - classic with big uploads behind a proxy limit.
415Unsupported Media TypeThe Content-Type is not something this endpoint parses.
418I’m a teapotAn April Fools RFC 2324 joke, now formally reserved - some servers still brew.
422Unprocessable ContentSyntactically valid, semantically wrong - the validation-error favorite of modern APIs.
429Too Many RequestsRate limiting hit - servers usually attach a Retry-After header saying when to come back.
451Unavailable For Legal ReasonsCensored by law - GDPR takedowns and national blocks identify themselves.
500Internal Server ErrorA generic server-side crash - the bug is in the server, not your request.
502Bad GatewayAn upstream server returned garbage - the proxy between you and the app is reporting the failure.
503Service UnavailableOverloaded or down for maintenance - often temporary, often with a Retry-After.
504Gateway TimeoutThe upstream server did not answer in time - the proxy gave up waiting.
The 28 status codes that cover virtually every response in real logs, verbatim from MDN's HTTP status reference. The pairs that get mixed up: 401 vs 403 (unauthenticated vs unauthorized - fix your login, not your permissions), 301 vs 308 (the permanent pair, differing only in whether the method may change), and 502 vs 504 (upstream answered garbage vs never answered). Bottom line: a SPA that renders “not found” while returning 200 is lying to every crawler - the soft-404 is the most expensive status-code mistake on the modern web. Debugging neighbors: URL parser, request bodies JSON to CSV and JSON formatter, payload types MIME types table.

The HTTP status code registry holds sixty-plus codes, but server logs live on about twenty-eight of them - and the errors people actually debug cluster in a dozen. This table carries the working set verbatim from MDN, filterable by code, class, or the symptom you are staring at.

The table is honest about the pairs everyone confuses: 401 means who are you while 403 means I know who you are and no; 301 and 308 are both permanent, differing only in whether the HTTP method survives the trip.

How to use

  1. Type a code (418), a name (redirect), or a symptom (timeout) - the table filters live.
  2. Click any code cell to copy it for an incident ticket or a bug report.
  3. Class chips jump to the 4xx client-error and 5xx server-error families - the two sides of every outage argument.

Frequently asked questions

What is the difference between 301, 302, 307 and 308?

Permanent vs temporary, and method preservation: 301 and 302 are the classics but let clients switch POST to GET; 307 and 308 are the strict versions that guarantee the method and body survive. Rule of thumb - moved APIs use 308, moved marketing pages use 301, everything temporary uses 307.

Why does my single-page app return 200 on a missing page?

The server delivers the app shell with 200 and the router decides afterward - a soft 404. Crawlers read the status line, see success, and index the nothing. Real fixes return a genuine 404 status from the server or render it client-side with a meta noindex.

When should I return 410 instead of 404?

When the removal is deliberate and permanent: 410 Gone tells crawlers to drop the URL faster and never re-check, while 404 leaves the URL in limbo. Content you deleted on purpose deserves 410; typos and private URLs stay 404.

What is 418 I’m a teapot?

An April Fools joke from the 1998 HTCPCP protocol (Hyper Text Coffee Pot Control Protocol) that became a beloved easter egg. The IETF reserved it officially in 2018 - it should never be sent, but some APIs return it on April 1 anyway.

Related tools