About this tool
This is a searchable guide to HTTP status codes, the three-digit numbers a web server sends back with every page, image and API call. It covers every code in the official IANA registry, checked against RFC 9110 (the current HTTP standard) and the newer RFCs that added codes such as 429 and 451, plus a clearly labelled set of unofficial codes you will meet in real life: Nginx’s 444 and 499, Laravel’s 419, and Cloudflare’s 520 to 530.
Each code opens to the same five parts: what it means in plain English, when you are likely to see it, what to do if you are just visiting the site, what to do if you run the site, and which headers go with it, such as Retry-After for 429 and 503 or Location for redirects. Where it makes sense, there is ready-to-copy code for sending that status from Express, Flask, PHP and Nginx.
It is written for developers who need the exact difference between 301 and 308, and for everyone else who just hit a 403 and wants to know whose fault it is.
How to use HTTP Status Codes
- Type a number or a few words into the search box, such as 404, “too many” or “cookie”. A three-digit match opens by itself.
- Or narrow the list with the buttons: 1xx Information, 2xx Success, 3xx Redirection, 4xx Client error, 5xx Server error, or Unofficial.
- Open a code to read what it means, when you will see it, and what to do as a visitor or as the site’s developer.
- Pick Express, Flask, PHP or Nginx above the code sample and press “Copy”. Your choice is remembered for every code.
- Press “Copy link” to share a direct link to that code. Adding #404 to this page’s address opens 404 straight away.
Searching “slow” finds 408 Request Timeout, 429 Too Many Requests and 504 Gateway Timeout. Opening 429 shows the Retry-After header and, in Express, res.set('Retry-After', '120') followed by res.status(429).
Features
- Every registered code from 100 Continue to 511 Network Authentication Required, including the WebDAV codes (207, 423, 507) and historic or deprecated ones, clearly marked.
- Common unofficial codes labelled with who uses them: 418, 419, 420, 444, 494–497, 499, 509 and Cloudflare’s 520–526 and 530.
- Plain-English meaning, when you will see it, and separate advice for visitors and for developers on every code.
- Related headers with a one-line explanation each, such as WWW-Authenticate, Allow, ETag and Content-Range.
- Copyable code for Express, Flask, PHP and Nginx, with the right headers and redirect syntax for each code.
- Search by number, by class (type 4xx), or by words found anywhere in a code’s description.
- Deep links: every code has its own address, like #404, that opens and highlights it.
- The source for every official code, down to the RFC section.
Tips and good to know
- 401 means “we don’t know who you are” and 403 means “we know, and the answer is no”. Logging in again only fixes a 401.
- Use 301 or 308 for permanent moves and 302 or 307 for temporary ones. The 307 and 308 pair keep the request method, so a POST stays a POST.
- A 502, 503 or 504 usually comes from a proxy or load balancer in front of the app, so look in the proxy’s logs as well as the app’s.
- Codes in the 520s with a Cloudflare page mean Cloudflare couldn’t get a good answer from the site’s own server. The site owner, not the visitor, has to fix them.
- Never send 200 with an error message inside. Browsers, caches, search engines and monitoring tools all trust the number.
Frequently asked questions
Does this page send anything about my searches anywhere?
No. The whole list is part of the page, and searching, filtering and copying all happen in your browser. Nothing you type is sent to AroraTools or anyone else.
Is it free, and can I use the code samples in my projects?
Yes to both. The guide is free with no sign-up, and the short code samples are simple enough to copy into any project.
Does it work on my phone and offline?
Yes. It works in any modern browser on phones, tablets and computers. Once the page has loaded, searching and opening codes keep working without a connection.
What is the difference between 404 and 410?
404 Not Found says nothing is at the address, without saying whether that is permanent. 410 Gone says the page existed and was removed on purpose for good, which helps search engines drop it sooner.
Is 418 I’m a teapot a real status code?
It began as an April Fools’ joke in 1998. RFC 9110 now lists 418 as reserved and unused so it never gets a real meaning, which is why it is marked unofficial here.
Why do I see a 499 in my logs that no one ever received?
499 is written by Nginx when the visitor closed the connection before the server replied, for example by closing the tab. It is never sent to anyone; many of them usually mean some responses are slow.
Page last reviewed
