Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

HTTP status codes are three-digit numbers that tell a client what happened to a request and what to do next. The first digit gives the broad class—informational, successful, redirection, client error or server error—while the specific code and response headers determine the practical meaning. This reference covers the registered codes, the distinctions that most often matter in debugging and API design, and how to handle codes you do not recognize.

How to read an HTTP status code

RFC 9110 defines a status code as a three-digit integer describing the result of a request and the semantics of its response, including whether it succeeded and what content is enclosed, if any. Valid HTTP status codes range from 100 through 599. The first digit identifies the class; the last two digits do not have a separate class-wide meaning.

Class Meaning Practical reading
1xx Informational An interim response; processing continues.
2xx Successful The request was received, understood and accepted, though the method and response determine what happened.
3xx Redirection Further action is needed to complete the request.
4xx Client error The request cannot be fulfilled as sent, or access is refused.
5xx Server error A server or intermediary failed to fulfill an apparently valid request.

Read the status alongside the HTTP method and headers. A 201 response, for example, usually indicates resource creation, while a 204 indicates success without response content. A status phrase such as “Not Found” is descriptive text; clients should rely on the numeric semantics and relevant headers, not assume every server uses the same phrase.

1xx: informational responses

A 1xx response is interim, ends at the header section and is followed by a final response. It is not the final result of the request. HTTP/1.0 servers must not send 1xx responses to HTTP/1.0 clients.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Code Meaning and use
100 Continue The server received the initial portion of the request and intends to continue once it receives the rest. Often used with Expect: 100-continue.
101 Switching Protocols The server agrees to switch application protocols in response to an Upgrade request.
102 Processing A registered WebDAV response used to indicate that processing is underway.
103 Early Hints Provides preliminary response headers before the final response.
104 Upload Resumption Supported A temporary registered extension. IANA lists it as registered on 2024-11-13, with the extension registered on 2025-09-15 and expiring on 2026-11-13. Its registration is time-limited; check the IANA registry for current status.

2xx: successful responses

A 2xx code means the request succeeded in the sense defined for its method; it does not mean every 2xx response has the same result or includes a body.

Code Meaning and use
200 OK The request succeeded. The response’s meaning depends on the method.
201 Created The request succeeded and created a resource. A Location header commonly identifies it.
202 Accepted The request was accepted for processing, but processing may not be complete.
203 Non-Authoritative Information The response metadata differs from the origin server’s representation.
204 No Content The request succeeded and the response has no content.
206 Partial Content The server is returning a requested range of a representation.
207 Multi-Status A registered extension with a specialized use.
208 Already Reported A registered extension with a specialized use.
226 IM Used A registered extension with a specialized use.

For client logic, distinguish “accepted” from “finished”: a 202 does not promise processing is complete. Likewise, a 204 is successful but should not be treated as a response containing a representation. Follow method semantics and relevant response headers.

3xx: redirection and cache responses

Some 3xx responses direct a client to another resource; 304 instead tells a client that a cached representation remains valid under the request’s conditional headers. For redirects, decide whether the request is temporary or permanent and whether the method and body must survive the redirect.

Code Meaning and behavior
300 Multiple Choices More than one representation may satisfy the request.
301 Moved Permanently The target has a permanent replacement. Clients and search systems may update references.
302 Found A temporary redirection. Historical user-agent behavior can change the method from POST to GET.
303 See Other Redirects to another resource, commonly for a subsequent retrieval using GET.
304 Not Modified The cached representation remains valid under the request’s conditional headers. The response carries no content.
305 Use Proxy Obsolete.
307 Temporary Redirect A temporary redirect that preserves the request method and body.
308 Permanent Redirect A permanent redirect that preserves the request method and body.

Choosing a redirect for an API or migration

  • Use 301 or 308 when the move is permanent; use 302 or 307 when it is temporary.
  • For a redirect where the method and body must be preserved, use 307 for temporary moves or 308 for permanent moves. The 301 and 302 family has historical method-changing behavior, particularly for POST.
  • Use 303 when the client should retrieve another resource with GET rather than repeat the original request as-is.
  • Provide an appropriate Location value so the client can identify the destination.

4xx: client errors and access problems

A 4xx response indicates a problem with the request, its authorization or a policy affecting access. Choose the most specific code that accurately describes the condition, and include an explanatory response where appropriate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Code Meaning and practical distinction
400 Bad Request The server cannot or will not process the request because of a perceived client error, such as malformed syntax or invalid framing.
401 Unauthorized Authentication credentials are missing or invalid. The server must send a WWW-Authenticate challenge.
403 Forbidden The server understood the request but refuses to fulfill it.
404 Not Found No current representation is available, or the server does not wish to disclose that one exists.
405 Method Not Allowed The method is known but unsupported for the target resource. The Allow header should identify supported methods.
406 Not Acceptable No representation matches the request’s proactive content-negotiation criteria.
408 Request Timeout The server did not receive a complete request in time.
409 Conflict The request conflicts with the current state of the target resource.
410 Gone The resource is intentionally and permanently unavailable.
411 Length Required The request requires a content length.
412 Precondition Failed A request precondition was not met.
413 Content Too Large The request content is too large for the server to process.
414 URI Too Long The request URI is too long for the server to process.
415 Unsupported Media Type The request content’s media type is not supported.
416 Range Not Satisfiable The requested range cannot be supplied.
417 Expectation Failed The server cannot meet the request’s stated expectation.
418 I’m a teapot An RFC-defined April Fools code, not a general-purpose application error choice.
421 Misdirected Request The request reached a server unable to produce a response for the target authority.
422 Unprocessable Content The content type and syntax are understood, but the instructions are semantically invalid.
423 Locked A specialized registered response.
424 Failed Dependency A specialized registered response.
425 Too Early A specialized registered response.
426 Upgrade Required The client should switch to another protocol.
428 Precondition Required The origin requires a conditional request.
429 Too Many Requests The client sent too many requests in a given period. Retry-After may communicate a backoff interval.
431 Request Header Fields Too Large The request headers are too large.
451 Unavailable For Legal Reasons Access is denied for legal reasons.

401 vs. 403

Use 401 when the client needs valid authentication credentials; the response must include a WWW-Authenticate challenge. Use 403 when the server understands the request but refuses it. A client that receives 403 should not assume that simply repeating the request unchanged will help.

404 vs. 410

Both indicate that the requested resource is unavailable, but 410 communicates that it is intentionally and permanently gone. A 404 can also be used when a server does not wish to disclose whether a representation exists.

400 vs. 422

400 covers a perceived client error such as malformed syntax or invalid framing. 422 is more specific: the content type and syntax are understood, but the instructions are semantically invalid.

5xx: server and intermediary errors

A 5xx response generally directs investigation toward the origin service, a gateway, a dependency, capacity or a deployment path. Which component is responsible depends on the system architecture.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Code Meaning and use
500 Internal Server Error A generic unexpected server condition.
501 Not Implemented The server does not support the functionality required to fulfill the request.
502 Bad Gateway A gateway or proxy received an invalid response from an upstream server.
503 Service Unavailable The server is temporarily unable to handle the request, commonly during overload or maintenance. Retry-After may help communicate when to try again.
504 Gateway Timeout A gateway or proxy did not receive a timely response from an upstream server.
505 HTTP Version Not Supported A specialized registered response indicating an unsupported HTTP version.
506 Variant Also Negotiates A specialized registered response.
507 Insufficient Storage A specialized registered response.
508 Loop Detected A specialized registered response.
510 Not Extended A specialized registered response.
511 Network Authentication Required A specialized registered response.

502 vs. 504

Both identify a gateway or proxy problem involving an upstream server, but they describe different conditions. A 502 means the gateway received an invalid upstream response; a 504 means it did not receive an upstream response in time. Check the gateway and upstream service path rather than assuming the client request itself is malformed.

Rank #4
Sale
HTTP: The Definitive Guide
  • Used Book in Good Condition
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do when a code is unfamiliar or non-standard

HTTP clients must understand the class of an unrecognized status code and treat it as the corresponding x00 code in that class. For example, an unknown 471 is handled as a 400-class client error. Values outside 100–599 are not valid HTTP status codes, although software libraries may use other numbers internally to report non-HTTP failures.

A code absent from a general reference may be a registered extension or specific to server software. Verify an unusual code against the IANA HTTP Status Code Registry and the relevant vendor’s documentation before assigning it portable meaning. Treat vendor-specific 5xx and 52x responses as non-standard until verified. Reason phrases can vary or be omitted; build client behavior around the numeric code and applicable headers.

Debugging checklist: diagnose the response, not just the number

  1. Confirm the response is HTTP. Separate an actual HTTP status from a local library error or a failure that occurred before an HTTP response was received.
  2. Record the method, target and request headers. For 405, check the method against Allow; for 406, inspect content-negotiation headers; for 415, verify the submitted media type.
  3. Check response headers that change the next action. Follow Location for redirects, use WWW-Authenticate to handle a 401 challenge, observe Retry-After for rate limits or temporary unavailability, and examine conditional headers for 304 or 412.
  4. For 4xx, correct the request or access condition. Validate syntax, payload meaning, credentials, authorization, current resource state and request rate before retrying.
  5. For 5xx, trace the server path. Identify whether the origin, proxy, gateway or dependency generated the response; distinguish an invalid upstream response from a timeout.
  6. Retry selectively. A 429 or temporary 503 may support a delayed retry when indicated by Retry-After. Do not blindly retry a malformed request, forbidden operation or permanent redirect as though all codes had the same recovery path.

Using status information in a screenshot workflow

When automating webpage captures, keep the HTTP result separate from the page-level outcome. ScreenshotNeo is a website screenshot API and MCP server: one GET request with a URL returns a PNG, JPEG or WebP screenshot, or a PDF. Its response includes X-Page-Verdict and X-Billed headers, which report page verdict and billing information; do not infer their meaning from an HTTP status code.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For example, this cURL request captures a page as WebP. See the ScreenshotNeo API documentation for the API details.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Or skip the browser setup

ScreenshotNeo accepts cookie or consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups and chat widgets before capture; each step can be turned off. Bot checks, blank pages, timeouts, failed loads and cache hits cost nothing. An MCP server exposes screenshot tools to Claude, Cursor and other MCP clients. The Free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 shots.

Sign up for ScreenshotNeo’s free plan.

Frequently Asked Questions

Does the phrase after a status code control how my client should behave?

No. Use the numeric status semantics and relevant response headers; the reason phrase can vary or be omitted.

Can an HTTP response have a status code outside 100–599?

No. A library may expose an out-of-range number for a local failure, but that is not a valid HTTP status code.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.