HTTP Status Codes

Look up any HTTP status code (1xx–5xx). Meaning, common causes, and the RFC reference.

Reading a status code

HTTP status codes are the three-digit numbers a server returns to a client to communicate the outcome of a request. They're grouped into five families: 1xx (informational), 2xx (success), 3xx (redirection), 4xx (client error), and 5xx (server error). Most developers know the common codes — 200, 301, 404, 500 — but the specification defines dozens more, and choosing the right one matters for API reliability, SEO, client behaviour, and debugging. This tool gives you the complete reference: meaning, use case, and the RFC where each code is formally defined.

Logs, API design, and production debugging

Searching and filtering by class

Codes that trip up even experienced developers

1xx through 5xx at a glance

RFC lineage and the search interface

Every HTTP response opens with a three-digit status code, and the first digit is the whole story in miniature: 1xx informational (the request is still in flight), 2xx success, 3xx redirection, 4xx the client got something wrong, 5xx the server did. The class-filter buttons narrow the table to one band at a time, and the search box matches on the number or the text — type 404, or type gateway to surface 502 and 504 together. Each row gives the reason phrase, the practical cause, and the defining RFC.

Most core codes now trace back to RFC 9110 (HTTP Semantics, 2022), which consolidated the older RFC 2616 / 7230–7235 series — so a modern citation reads "RFC 9110 §15.x" rather than the scattered references you'll still see in older docs. Specialist codes keep their own RFCs: 429 and 431 from RFC 6585, 451 from RFC 7725, the WebDAV range (207, 422, 423…) from RFC 4918.

Choosing between similar codes

401 or 403 — what's the difference? 401 Unauthorized actually means unauthenticated: you haven't proven who you are, and a login challenge should follow. 403 Forbidden means you're authenticated but not allowed — a login prompt won't help, so don't send one.

Which redirect should I return — 301, 302, 307 or 308? Use 301/308 for permanent moves and 302/307 for temporary ones. The modern pair (307/308) explicitly preserves the request method and body; the legacy pair (301/302) historically let clients silently turn a POST into a GET. If a POST must stay a POST across the redirect, pick 307 or 308.

400 or 422 for a bad request body? 400 Bad Request is for malformed syntax the server can't even parse (broken JSON, a missing required header). 422 Unprocessable Content is for a body that parses fine but fails your validation rules — right shape, wrong values.

Which 5xx should a reverse proxy return? 502 Bad Gateway when the upstream replied with garbage, 504 Gateway Timeout when it didn't reply in time, and 503 Service Unavailable when you're deliberately down or overloaded — pair 503 and 429 with a Retry-After header so clients back off sensibly.