HTTP Status Codes
Every HTTP status code explained in plain language: what it means, common causes, how to fix it, an example response and the RFC that defines it.
70 status codes
1xx Informational
Interim responses: the request was received and processing continues.
100 Continue The server has received the request headers and the client may go ahead and send the body. It is an interim response sent before the final status. 101 Switching Protocols The server agrees to switch to the protocol the client asked for in the Upgrade header, most often WebSocket. After this response the connection speaks the new protocol. 102 Processing A WebDAV interim response telling the client the server is still working on a long request, so it should not time out yet. It is deprecated and rarely sent today. 103 Early Hints An interim response that sends Link headers early so the browser can preload CSS, fonts or preconnect to origins while the server is still building the final page.
2xx Success
The request was received, understood and accepted.
200 OK The request succeeded. For GET the body contains the resource; for POST it contains the result of the action. 201 Created The request succeeded and created a new resource. The Location header usually points to it. 202 Accepted The request was accepted for processing, but processing has not finished. The outcome is unknown at response time. 203 Non-Authoritative Information The request succeeded, but a transforming proxy modified the payload from the origin's 200 response. 204 No Content The request succeeded and there is no body to return. Headers may still carry metadata such as a new ETag. 205 Reset Content The request succeeded and the client should reset the document view, for example clear the form that was submitted. No body is sent. 206 Partial Content The server is returning only part of the resource, as requested by a Range header. Content-Range says which bytes are included. 207 Multi-Status A WebDAV response whose XML body contains a separate status for each of several resources affected by one request. 208 Already Reported Used inside a WebDAV 207 body to say a resource was already listed earlier in the response, avoiding duplicates when bindings create loops. 226 IM Used The server fulfilled a GET with one or more instance manipulations (delta encoding) applied, so the body is a diff, not the full resource.
3xx Redirection
The client must take another step, usually follow a new URL.
300 Multiple Choices The resource has several representations (language, format) and the client or user should pick one. The server may suggest a preferred one via Location. 301 Moved Permanently The resource has moved permanently to the URL in Location. Clients and search engines should use the new URL from now on. 302 Found The resource is temporarily at another URL. Clients should keep using the original URL for future requests. 303 See Other The server directs the client to fetch another URL with GET, typically to show the result of a POST. 304 Not Modified The cached copy the client already has is still valid, so the server sends no body. It answers a conditional request with If-None-Match or If-Modified-Since. 305 Use Proxy Deprecated. It once told the client to repeat the request through the proxy in Location. Browsers ignore it for security reasons. 307 Temporary Redirect The resource is temporarily at another URL, and the client must repeat the request there with the same method and body. 308 Permanent Redirect The resource has moved permanently, and clients must repeat the request at the new URL with the same method and body.
4xx Client errors
The request has a problem the client should fix.
400 Bad Request The server cannot process the request because it is malformed: invalid syntax, bad framing or values it cannot parse. 401 Unauthorized The request lacks valid authentication credentials. Despite the name it means unauthenticated: log in or send a valid token. 402 Payment Required Reserved for future use, but in practice services return it when payment or a paid plan is required to continue. 403 Forbidden The server understood the request but refuses to authorize it. Logging in again will not help unless permissions change. 404 Not Found The server cannot find anything at the requested URL. It says nothing about whether the resource ever existed or might return. 405 Method Not Allowed The URL exists but does not support the HTTP method used. The Allow header lists the methods that work. 406 Not Acceptable The server cannot produce a response in any format the client's Accept headers allow. 407 Proxy Authentication Required A proxy between the client and server requires authentication before forwarding the request. 408 Request Timeout The server closed the connection because the client did not send a complete request in time. 409 Conflict The request conflicts with the current state of the resource, such as a duplicate or a concurrent edit. 410 Gone The resource is permanently gone and no forwarding address is known. Unlike 404, the server states this on purpose. 411 Length Required The server requires a Content-Length header and the request did not include one. 412 Precondition Failed A precondition in the request headers, such as If-Match or If-Unmodified-Since, evaluated to false, so the server did not apply the request. 413 Content Too Large The request body is larger than the server is willing or able to process. Formerly called Payload Too Large. 414 URI Too Long The request URL is longer than the server will interpret. 415 Unsupported Media Type The server refuses the request because the body's media type (Content-Type) or encoding is not supported. 416 Range Not Satisfiable The Range header asks for bytes outside the size of the resource. 417 Expectation Failed The server cannot meet the requirement in the request's Expect header, usually Expect: 100-continue. 418 I'm a teapot An April Fools' joke from the Hyper Text Coffee Pot Control Protocol: the server is a teapot and refuses to brew coffee. Some sites use it as a joke or to block bots. 421 Misdirected Request The request reached a server that is not configured to answer for that host, often because an HTTP/2 connection was reused for a different domain. 422 Unprocessable Content The request is well-formed but contains semantic errors, so the server cannot process it. Formerly Unprocessable Entity. 423 Locked WebDAV: the resource is locked, so the method cannot be applied. 424 Failed Dependency WebDAV: the action failed because it depended on another action in the same request that failed. 425 Too Early The server refuses to process a request sent in TLS 1.3 early data (0-RTT) because it could be replayed. 426 Upgrade Required The server refuses the request with the current protocol and requires the client to upgrade, for example to TLS or HTTP/2, as named in the Upgrade header. 428 Precondition Required The server requires the request to be conditional (If-Match etc.) to prevent lost updates. 429 Too Many Requests The client sent too many requests in a given time (rate limiting). Retry-After may say how long to wait. 431 Request Header Fields Too Large The request's headers are too large, either one header or all headers together. 451 Unavailable For Legal Reasons The server cannot provide the resource for legal reasons, such as a court order or government censorship. The number nods to Fahrenheit 451. 499 Client Closed Request (Non-standard) nginx logs 499 when the client closed the connection before the server sent a response. The client never sees this code.
5xx Server errors
The server failed to fulfil a valid request.
500 Internal Server Error The server hit an unexpected condition and could not complete the request. It is a generic catch-all for server-side errors. 501 Not Implemented The server does not support the functionality required, typically the request method itself. 502 Bad Gateway A gateway or proxy received an invalid response from the upstream server it forwarded the request to. 503 Service Unavailable The server is temporarily unable to handle the request, due to overload or maintenance. Retry-After may say when to try again. 504 Gateway Timeout A gateway or proxy did not receive a timely response from the upstream server. 505 HTTP Version Not Supported The server does not support the HTTP version used in the request. 506 Variant Also Negotiates Transparent content negotiation is misconfigured: the chosen variant is itself set up to negotiate, creating a loop. 507 Insufficient Storage The server cannot store the representation needed to complete the request (out of disk space or quota). Originates in WebDAV. 508 Loop Detected The server detected an infinite loop while processing a request with Depth: infinity (WebDAV). Some hosts also use it for resource limits. 510 Not Extended Further extensions are required for the server to fulfill the request (HTTP Extension Framework). The framework is now historic. 511 Network Authentication Required The client must authenticate to gain network access, typically on a captive portal (hotel or airport Wi-Fi). 520 Web Server Returned an Unknown Error (Non-standard) Cloudflare-specific: the origin server returned an empty, unknown or unexpected response. 521 Web Server Is Down (Non-standard) Cloudflare-specific: the origin server refused the connection. 522 Connection Timed Out (Non-standard) Cloudflare-specific: the TCP connection to the origin timed out. 523 Origin Is Unreachable (Non-standard) Cloudflare-specific: Cloudflare cannot reach the origin, typically because of DNS or routing problems. 524 A Timeout Occurred (Non-standard) Cloudflare-specific: a connection to the origin was made, but the origin did not send an HTTP response in time (100 seconds by default). 525 SSL Handshake Failed (Non-standard) Cloudflare-specific: the TLS handshake between Cloudflare and the origin failed. 526 Invalid SSL Certificate (Non-standard) Cloudflare-specific: in Full (strict) SSL mode, the origin's certificate is invalid, expired, self-signed or does not match the host name.