HTTP Status Codes Cheat Sheet

Every server response starts with a three-digit status code. The first digit tells you the class: 1xx information, 2xx success, 3xx redirect, 4xx client error, 5xx server error.

73 quick references · 8 sections · Updated October 2026

The five classes

1xx Informational
The request was received and the server is still working on it.
2xx Success
The request worked.
3xx Redirection
The client must go somewhere else, or use a cached copy, to finish the request.
4xx Client error
The request is wrong or not allowed. The problem is on the client side.
5xx Server error
The request looked fine but the server failed to handle it.

1xx: Informational

100 Continue
The headers were accepted. The client can go ahead and send the request body.
101 Switching Protocols
The server agrees to switch protocol, for example upgrading to WebSocket.
102 Processing
The server has the request and is still working. Used in WebDAV.
103 Early Hints
Sends preload hints for CSS or JS while the final response is being prepared.

2xx: Success

200 OK
The standard success response. The body contains the result.
201 Created
A new resource was created, typically after a POST. Send its URL in the Location header.
202 Accepted
The request was accepted but is processed later, such as a background job.
203 Non-Authoritative Information
Success, but the data came from a proxy or copy rather than the original server.
204 No Content
Success with nothing to return. Common for DELETE and some PUT requests.
205 Reset Content
Success, and the client should reset the form or view that sent the request.
206 Partial Content
Only part of the file was sent. Used for video streaming and resumed downloads (Range requests).

3xx: Redirection

300 Multiple Choices
There are several possible responses and the client should pick one. Rarely used.
301 Moved Permanently
The URL has changed for good. Browsers and search engines update to the new address.
302 Found
A temporary redirect. The old URL stays the main one.
303 See Other
Go to another URL with a GET request. Often used after a form POST.
304 Not Modified
Your cached copy is still current, so no body is sent. Saves bandwidth.
307 Temporary Redirect
Like 302, but the client must repeat the same method and body.
308 Permanent Redirect
Like 301, but the client must repeat the same method and body.

4xx: Client errors

400 Bad Request
The server cannot understand the request: malformed syntax, bad JSON or invalid fields.
401 Unauthorized
You must authenticate first. No valid login or token was supplied.
402 Payment Required
Reserved for payment systems. Some APIs use it for billing or quota limits.
403 Forbidden
The server knows who you are but you are not allowed to do this.
404 Not Found
No resource exists at this URL. The most famous error.
405 Method Not Allowed
The URL exists but not for this method, such as POST on a read-only endpoint.
406 Not Acceptable
The server cannot produce a response in the format the client asked for.
408 Request Timeout
The client took too long to send the request.
409 Conflict
The request clashes with the current state, such as a duplicate username or an edit conflict.
410 Gone
The resource used to exist and was removed on purpose. Tells search engines to drop it.
411 Length Required
The server requires a Content-Length header.
412 Precondition Failed
A condition in the request headers, like If-Match, was not met.
413 Content Too Large
The request body is bigger than the server accepts, such as an oversized upload.
414 URI Too Long
The URL is longer than the server will handle.
415 Unsupported Media Type
The body format is not supported, for example sending XML when only JSON is accepted.
416 Range Not Satisfiable
The requested byte range does not exist in the file.
418 I'm a teapot
A joke status from an April Fools RFC. Sometimes used for fun or to block bots.
422 Unprocessable Content
The request is well-formed but its data fails validation. Popular in APIs for form errors.
423 Locked
The resource is locked. Used in WebDAV.
425 Too Early
The server will not process a request that might be replayed.
426 Upgrade Required
The client must switch to a newer protocol, such as HTTPS or HTTP/2.
428 Precondition Required
The server insists the request be conditional, to prevent lost updates.
429 Too Many Requests
Rate limit hit. Wait and retry, often using the Retry-After header.
431 Request Header Fields Too Large
The headers, or one header such as a cookie, are too big.
451 Unavailable For Legal Reasons
The content is blocked for legal reasons such as a court order.

5xx: Server errors

500 Internal Server Error
A general failure: something unexpected broke on the server, often a bug or unhandled exception.
501 Not Implemented
The server does not support the feature or method needed.
502 Bad Gateway
A gateway or proxy got an invalid response from the server behind it.
503 Service Unavailable
The server is down for maintenance or overloaded. It may include Retry-After.
504 Gateway Timeout
A gateway or proxy waited too long for the upstream server.
505 HTTP Version Not Supported
The server does not support the HTTP version used.
507 Insufficient Storage
The server has run out of storage space. Used in WebDAV.
508 Loop Detected
The server found an infinite loop while processing the request.
511 Network Authentication Required
You must log in to the network first, such as on a hotel Wi-Fi portal.

Which code should my API return?

GET succeeded
200 OK with the data in the body.
POST created something
201 Created with the new item or its Location.
DELETE or PUT with nothing to return
204 No Content.
Invalid or missing fields
400 Bad Request, or 422 if the request is valid but the data fails validation.
Not logged in
401 Unauthorized.
Logged in but not allowed
403 Forbidden.
Item does not exist
404 Not Found.
Duplicate or conflicting data
409 Conflict.
Too many requests
429 Too Many Requests.
Unexpected crash
500 Internal Server Error. Never leak stack traces to clients.
Page moved for good
301 Moved Permanently, so search engines transfer the ranking.
Page moved for now
302 Found or 307 Temporary Redirect.

Status codes and SEO

200 on real pages
Only pages that exist and can be indexed should return 200.
301 for moved pages
Use it when a URL changes so visitors and ranking signals follow the move.
404 or 410 for removed pages
Return a real 404 or 410. A "not found" message served with 200 is a soft 404 and confuses Google.
503 for downtime
Tells crawlers the outage is temporary, so they come back and keep your pages indexed.

More cheat sheets