HTTP Status Codes Cheat Sheet
Every server response starts with a three-digit status code. The first digit tells you the class: 1xx information, 2xx success, 3xx redirect, 4xx client error, 5xx server error.
Nothing matches your search.
The five classes
1xx Informational- The request was received and the server is still working on it.
2xx Success- The request worked.
3xx Redirection- The client must go somewhere else, or use a cached copy, to finish the request.
4xx Client error- The request is wrong or not allowed. The problem is on the client side.
5xx Server error- The request looked fine but the server failed to handle it.
1xx: Informational
100 Continue- The headers were accepted. The client can go ahead and send the request body.
101 Switching Protocols- The server agrees to switch protocol, for example upgrading to WebSocket.
102 Processing- The server has the request and is still working. Used in WebDAV.
103 Early Hints- Sends preload hints for CSS or JS while the final response is being prepared.
2xx: Success
200 OK- The standard success response. The body contains the result.
201 Created- A new resource was created, typically after a POST. Send its URL in the Location header.
202 Accepted- The request was accepted but is processed later, such as a background job.
203 Non-Authoritative Information- Success, but the data came from a proxy or copy rather than the original server.
204 No Content- Success with nothing to return. Common for DELETE and some PUT requests.
205 Reset Content- Success, and the client should reset the form or view that sent the request.
206 Partial Content- Only part of the file was sent. Used for video streaming and resumed downloads (Range requests).
3xx: Redirection
300 Multiple Choices- There are several possible responses and the client should pick one. Rarely used.
301 Moved Permanently- The URL has changed for good. Browsers and search engines update to the new address.
302 Found- A temporary redirect. The old URL stays the main one.
303 See Other- Go to another URL with a GET request. Often used after a form POST.
304 Not Modified- Your cached copy is still current, so no body is sent. Saves bandwidth.
307 Temporary Redirect- Like 302, but the client must repeat the same method and body.
308 Permanent Redirect- Like 301, but the client must repeat the same method and body.
4xx: Client errors
400 Bad Request- The server cannot understand the request: malformed syntax, bad JSON or invalid fields.
401 Unauthorized- You must authenticate first. No valid login or token was supplied.
402 Payment Required- Reserved for payment systems. Some APIs use it for billing or quota limits.
403 Forbidden- The server knows who you are but you are not allowed to do this.
404 Not Found- No resource exists at this URL. The most famous error.
405 Method Not Allowed- The URL exists but not for this method, such as POST on a read-only endpoint.
406 Not Acceptable- The server cannot produce a response in the format the client asked for.
408 Request Timeout- The client took too long to send the request.
409 Conflict- The request clashes with the current state, such as a duplicate username or an edit conflict.
410 Gone- The resource used to exist and was removed on purpose. Tells search engines to drop it.
411 Length Required- The server requires a Content-Length header.
412 Precondition Failed- A condition in the request headers, like If-Match, was not met.
413 Content Too Large- The request body is bigger than the server accepts, such as an oversized upload.
414 URI Too Long- The URL is longer than the server will handle.
415 Unsupported Media Type- The body format is not supported, for example sending XML when only JSON is accepted.
416 Range Not Satisfiable- The requested byte range does not exist in the file.
418 I'm a teapot- A joke status from an April Fools RFC. Sometimes used for fun or to block bots.
422 Unprocessable Content- The request is well-formed but its data fails validation. Popular in APIs for form errors.
423 Locked- The resource is locked. Used in WebDAV.
425 Too Early- The server will not process a request that might be replayed.
426 Upgrade Required- The client must switch to a newer protocol, such as HTTPS or HTTP/2.
428 Precondition Required- The server insists the request be conditional, to prevent lost updates.
429 Too Many Requests- Rate limit hit. Wait and retry, often using the Retry-After header.
431 Request Header Fields Too Large- The headers, or one header such as a cookie, are too big.
451 Unavailable For Legal Reasons- The content is blocked for legal reasons such as a court order.
5xx: Server errors
500 Internal Server Error- A general failure: something unexpected broke on the server, often a bug or unhandled exception.
501 Not Implemented- The server does not support the feature or method needed.
502 Bad Gateway- A gateway or proxy got an invalid response from the server behind it.
503 Service Unavailable- The server is down for maintenance or overloaded. It may include Retry-After.
504 Gateway Timeout- A gateway or proxy waited too long for the upstream server.
505 HTTP Version Not Supported- The server does not support the HTTP version used.
507 Insufficient Storage- The server has run out of storage space. Used in WebDAV.
508 Loop Detected- The server found an infinite loop while processing the request.
511 Network Authentication Required- You must log in to the network first, such as on a hotel Wi-Fi portal.
Which code should my API return?
GET succeeded- 200 OK with the data in the body.
POST created something- 201 Created with the new item or its Location.
DELETE or PUT with nothing to return- 204 No Content.
Invalid or missing fields- 400 Bad Request, or 422 if the request is valid but the data fails validation.
Not logged in- 401 Unauthorized.
Logged in but not allowed- 403 Forbidden.
Item does not exist- 404 Not Found.
Duplicate or conflicting data- 409 Conflict.
Too many requests- 429 Too Many Requests.
Unexpected crash- 500 Internal Server Error. Never leak stack traces to clients.
Page moved for good- 301 Moved Permanently, so search engines transfer the ranking.
Page moved for now- 302 Found or 307 Temporary Redirect.
Status codes and SEO
200 on real pages- Only pages that exist and can be indexed should return 200.
301 for moved pages- Use it when a URL changes so visitors and ranking signals follow the move.
404 or 410 for removed pages- Return a real 404 or 410. A "not found" message served with 200 is a soft 404 and confuses Google.
503 for downtime- Tells crawlers the outage is temporary, so they come back and keep your pages indexed.