🔢 HTTP Status Code Reference
Search by code or keyword (e.g. "404" or "not found") to find any standard HTTP status code and what it means.
Reading a code from its first digit
The leading digit is the whole classification, and the reference colours each card by it. Fifty-three codes are listed: 4 informational, 7 success, 7 redirection, 26 client errors and 9 server errors.
1xx informational the request was received, keep going
2xx success it worked
3xx redirection go somewhere else to finish
4xx client error the request itself is wrong - resending it unchanged will fail again
5xx server error the request may be fine; the server could not answer
Search matches the number, the name and the description, so 429,
rate and too many all reach the same card. Rarely-seen WebDAV
codes such as 207 and 423 are left out.
Distinctions that catch people out
- 301 and 302 versus 307 and 308. The older pair let a client turn a POST into a GET when it follows the redirect; the newer pair guarantee the method and body survive. Use 308 or 307 for anything that is not a plain page move.
- 304 is not an error. It answers a conditional request carrying
If-None-Matchand means the cached copy is still good, so no body is sent. - 502 versus 504. Both come from something in front of your application: 502 means the upstream replied with nonsense, 504 means it did not reply in time.
curl -I.Frequently asked questions
What is the difference between 401 and 403?
401 means the server does not know who you are - credentials are missing, expired or
wrong, and it should send a WWW-Authenticate header. 403 means it knows
exactly who you are and you still may not have this. Retrying with a fresh token fixes
a 401, never a 403.
Should a redirect be 301 or 302?
301 for a permanent move: search engines transfer the ranking signals, and browsers cache it aggressively, so a mistake is painful to undo. 302 or 307 for anything temporary, such as a maintenance page or a locale-based bounce.
What causes 502 Bad Gateway?
A proxy, load balancer or CDN got an invalid or empty response from the application behind it - usually a crash, an out-of-memory kill, or nothing listening on the expected port. Nothing on the client side can fix it; check the origin's logs.