Every HTTP response carries a 3-digit status code, and the first digit alone tells you the category of what happened — informational, success, redirection, client error, or server error. Knowing the five categories gets you most of the way to understanding an unfamiliar code on sight; the specific codes below are the ones worth knowing by number because they show up constantly or are commonly confused with a near-neighbor.
The five categories
- 1xx — Informational. The request was received and processing continues; rarely seen directly in application code (e.g.
101 Switching Protocolsfor a WebSocket upgrade). - 2xx — Success. The request was received, understood, and accepted.
- 3xx — Redirection. Further action is needed to complete the request, usually following a different URL.
- 4xx — Client Error. The request itself was malformed, unauthorized, or otherwise the client's fault.
- 5xx — Server Error. The request looked fine, but the server failed to fulfill it.
Codes worth knowing by number
- 200 OK — the request succeeded; for GET, the response body is the resource itself.
- 201 Created — succeeded and a new resource now exists, typically after POST/PUT.
- 204 No Content — succeeded, nothing to return — common after a DELETE.
- 301 / 308 — permanent redirect (308 explicitly preserves the original HTTP method; 301 historically allowed clients to switch a POST to a GET on the follow-up request).
- 302 / 307 — temporary redirect (307 explicitly preserves the method; 302's method behavior on the follow-up has always been inconsistent across clients, which is why 307 exists).
- 304 Not Modified — the client's cached copy is still valid; no body is sent.
- 400 Bad Request — the server couldn't parse or understand the request as sent.
- 404 Not Found — no resource exists at this URL (or the server won't say why).
- 422 Unprocessable Entity — the request was well-formed but failed semantic/validation rules (e.g. a required field was missing).
- 429 Too Many Requests — the client is being rate-limited.
- 500 Internal Server Error — a generic, unhandled failure on the server.
- 504 Gateway Timeout — an upstream server the gateway depends on didn't respond in time.
Commonly confused pairs
401 Unauthorized vs. 403 Forbidden — despite the name, 401 actually means "unauthenticated": the request presents no credentials, or invalid/expired ones, and the client is expected to (re-)authenticate. 403 means the server knows exactly who's asking — the credentials are valid — but that identity specifically isn't permitted to access this resource. The distinguishing question isn't whether a differentaccount might work (a different, authorized account logging in could well fix a 403 too) — it's whether this request's own credentials are valid at all. No valid credentials → 401. Valid credentials, but this identity lacks permission → 403, and re-sending the same credentials again won't change the outcome.
502 Bad Gateway vs. 503 Service Unavailable — a 502 means a server acting as a gateway or proxy got an invalid or no response from the upstream server it was trying to reach. A 503 means the server itself is temporarily unable to handle the request — overloaded, or down for maintenance — and is often sent with a Retry-After header. Broadly: 502 points at a failure one hop further upstream; 503 is the responding server describing its own state.
404 Not Found vs. 410 Gone — 404 says nothing about whether the resource ever existed or might come back. 410 is a deliberate, stronger statement: the resource used to exist and has been intentionally, permanently removed — a signal search engines and caches are meant to take more seriously than a plain 404.
Try it yourself
Search our full HTTP Status Code Reference for a plain-English explanation of any code, 1xx through 5xx.