1xx — Informational

100
Continue The headers arrived and look fine; send the body.
101
Switching Protocols Switching to another protocol on the same connection — how a WebSocket handshake ends.
102
Processing WebDAV: still working on it, keep waiting.
103
Early Hints Preload hints sent ahead of the real response, so the browser can start fetching early.

2xx — Success

200
OK It worked. For GET the body is the resource; for POST it is the result.
201
Created Something new exists now, and the Location header says where.
202
Accepted Taken for processing, not finished — and no promise that it will succeed.
203
Non-Authoritative Information A proxy changed the body on the way, so this is not exactly what the origin sent.
204
No Content It worked and there is deliberately no body. The page should not navigate anywhere.
205
Reset Content It worked; clear the form the user just submitted.
206
Partial Content Only the requested byte range was sent — how video seeking and resumed downloads work.
207
Multi-Status WebDAV: one response carrying a separate status for each operation in a batch.
208
Already Reported WebDAV: this member was already listed earlier in the same response.
226
IM Used The response is the result of applying deltas to the copy the client already has.

3xx — Redirection

300
Multiple Choices Several representations exist and the client has to choose. Rare in practice.
301
Moved Permanently The address changed for good. Browsers and search engines cache this hard, so mean it.
302
Found Temporary, but old clients may turn a POST into a GET — use 307 when that matters.
303
See Other Go and GET this other address instead — the standard answer to a form POST.
304
Not Modified Your cached copy is still good; nothing but headers is sent.
307
Temporary Redirect Like 302, except the method and body are guaranteed to survive.
308
Permanent Redirect Like 301, except the method and body are guaranteed to survive.

4xx — Client error

400
Bad Request The request itself is malformed. This is about syntax, not about permission.
401
Unauthorized Not authenticated. The name is misleading: 403 is the one that means unauthorized.
402
Payment Required Reserved for payment, never standardised; a few APIs use it for quota problems.
403
Forbidden Who you are is known and the answer is still no. Repeating the request will not help.
404
Not Found Nothing at this address — or the server would rather not admit that there is.
405
Method Not Allowed The address exists but not with this verb; the Allow header lists the ones that work.
406
Not Acceptable Nothing on offer matches the Accept header the client sent.
407
Proxy Authentication Required Like 401, except it is the proxy asking rather than the server.
408
Request Timeout The client took too long to send the request, so the connection was closed.
409
Conflict The request collides with the current state — an edit against a version that moved on.
410
Gone It existed and was deliberately removed. Unlike 404, this says do not come back.
411
Length Required The server refuses a body that arrives without a Content-Length.
412
Precondition Failed An If-Match or If-Unmodified-Since condition did not hold, so nothing was changed.
413
Content Too Large The body is larger than the server accepts — usually an upload limit.
414
URI Too Long The address is longer than the server will parse; often a GET that should be a POST.
415
Unsupported Media Type The Content-Type is not one this endpoint knows how to read.
416
Range Not Satisfiable The requested byte range falls outside the file.
417
Expectation Failed The Expect header asked for something the server will not do.
418
I'm a teapot An April Fools' joke from 1998 that half the frameworks in the world still implement.
421
Misdirected Request This connection cannot serve this host — seen with HTTP/2 connection reuse.
422
Unprocessable Content The syntax is fine but the content fails validation — the usual answer for a bad field.
423
Locked WebDAV: the resource is locked by someone else.
424
Failed Dependency WebDAV: an earlier request in the same batch failed, so this one was not attempted.
425
Too Early The server will not risk replaying a request that arrived in TLS early data.
426
Upgrade Required The client has to switch protocols first — usually to a newer TLS version.
428
Precondition Required Send an If-Match, so two clients cannot silently overwrite each other.
429
Too Many Requests Rate limited. The Retry-After header says how long to wait.
431
Request Header Fields Too Large The headers are too large — most often one enormous cookie.
451
Unavailable For Legal Reasons Blocked for legal reasons. The number is a nod to Fahrenheit 451.

5xx — Server error

500
Internal Server Error The server broke and has nothing more specific to say.
501
Not Implemented The server does not support this method at all — unlike 405, which is per address.
502
Bad Gateway A proxy asked the upstream server and got back something it could not use.
503
Service Unavailable Down on purpose or overloaded. Meant to be temporary, and should carry Retry-After.
504
Gateway Timeout A proxy waited for the upstream server and gave up.
505
HTTP Version Not Supported The server refuses the HTTP version in the request line.
506
Variant Also Negotiates A content negotiation loop on the server's side.
507
Insufficient Storage WebDAV: no room left to store what the request would create.
508
Loop Detected WebDAV: the operation runs in circles and was stopped.
510
Not Extended The request needs an extension that the server requires but did not receive.
511
Network Authentication Required A captive portal: log in to the network before anything else will work.

Good to know

  • The first digit is the whole answer: 2 worked, 3 look elsewhere, 4 you got it wrong, 5 we got it wrong.
  • 401 and 403 are the pair people mix up. 401 means we do not know who you are; 403 means we do, and the answer is still no.
  • Prefer 307 and 308 over 302 and 301 when a POST must stay a POST: the older pair leaves that to the client, and old clients change the method.
  • The reason phrases are shown as they travel on the wire, in English — HTTP/2 does not send them at all, and no client should read them.
29 views
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.