Tools marked “Coming soon” are being built now.

Developer tools
Developer · Free · Private

HTTP Status Codes

Search any status code and find out what it means, why you’re seeing it and what to do next.

  • Runs in your browser
  • No upload
  • No sign-up

Most looked up:200301302304400401403404405429500502503504

80 codes: 62 registered with IANA, 18 unofficial

1xx Information

Interim replies: the request is still in progress.

100ContinueGo ahead and send the request body.

An interim reply: the server has received the request headers and is happy for the client to send the body. The final status code follows later.

When you’ll see it
Only in tools that show raw traffic, when a client sends Expect: 100-continue before a large upload (curl does this for bigger POSTs).
If you’re visiting the site
Nothing. Browsers handle it invisibly.
If you run the site
Usually nothing: servers answer Expect: 100-continue automatically. Reject early with 417 or a 4xx if you can tell from the headers that the upload will fail.

Related headers

  • Expect Request header; “100-continue” asks the server to approve the body before it is sent.

Your web server or framework sends this itself while handling the connection; application code normally never sets it.

Defined in RFC 9110 §15.2.1

101Switching ProtocolsThe connection is switching to another protocol.

The server agrees to the client’s Upgrade request and switches the connection to the protocol named in the Upgrade header, almost always WebSocket.

When you’ll see it
In the browser’s Network tab when a page opens a WebSocket (chat, live dashboards, multiplayer games).
If you’re visiting the site
Nothing; this is normal.
If you run the site
Let your WebSocket library send it. If you get 400 or 426 instead, check that proxies pass the Upgrade and Connection headers through (Nginx needs proxy_set_header for both).

Related headers

  • Upgrade Names the protocol to switch to, such as websocket.
  • Connection Controls the connection itself; must include “upgrade” when switching protocols.

Your web server or framework sends this itself while handling the connection; application code normally never sets it.

Defined in RFC 9110 §15.2.2

102ProcessingStill working on it (old WebDAV code).Deprecated

An interim reply from WebDAV servers saying a long request is still being worked on, to stop the client timing out. Later WebDAV specs dropped it, though it remains registered.

When you’ll see it
Rarely, from WebDAV file servers during long copy or move operations.
If you’re visiting the site
Nothing; wait for the final answer.
If you run the site
Avoid it in new APIs. For long jobs, reply 202 Accepted with a link where the client can check progress.

Your web server or framework sends this itself while handling the connection; application code normally never sets it.

Defined in RFC 2518 §10.1

103Early HintsStart loading these files while the page is prepared.

An interim reply sent before the real response, carrying Link headers so the browser can start preloading stylesheets, scripts or fonts while the server is still building the page.

When you’ll see it
In the Network tab of Chrome, Edge and Firefox on sites that use it, often via a CDN such as Cloudflare.
If you’re visiting the site
Nothing. It just makes pages load sooner.
If you run the site
Send it for slow pages with known critical files. In Node, res.writeEarlyHints({ link: [...] }) sends it; many CDNs can turn your Link headers into 103s for you.

Related headers

  • Link Points to related resources; with 103 it tells the browser what to preload early.

Sent with a special call (Node’s res.writeEarlyHints) or by a CDN, not as the final status of a response.

Defined in RFC 8297

2xx Success

The request worked.

200OKIt worked.

The request succeeded. For GET the body is the thing asked for; for POST it is the result of the action.

When you’ll see it
Behind almost every page, image and API call that works.
If you’re visiting the site
Nothing to do.
If you run the site
Use it for successful reads and actions that return content. Don’t return 200 with an error message in the body — clients, caches and monitoring all trust the status code.

Related headers

  • Content-Type The format of the body, such as application/json.
  • Cache-Control Rules for how long and where a response may be cached.
  • ETag A fingerprint of the current version, used to check whether a cached copy is still current.

Defined in RFC 9110 §15.3.1

201CreatedA new resource was created.

The request succeeded and created something new. The Location header should give its address.

When you’ll see it
After signing up, posting a comment or creating a record through an API.
If you’re visiting the site
Nothing to do; it worked.
If you run the site
Return it from POST (or PUT to a new address) and set Location to the new item, ideally returning the item in the body too.

Related headers

  • Location Response header with the address to go to (redirects) or of the thing just created (201).
  • ETag A fingerprint of the current version, used to check whether a cached copy is still current.

Defined in RFC 9110 §15.3.2

202AcceptedAccepted, but not finished yet.

The request was received and queued, but the work isn’t done and might still fail later. HTTP has no way to report the final outcome on this response.

When you’ll see it
From APIs that start long jobs: video encoding, exports, sending bulk email.
If you’re visiting the site
Wait, or check back later for the result.
If you run the site
Return a link (in the body or Location) where the client can poll the job’s status, and a sensible Retry-After if you want to pace polling.

Related headers

  • Location Response header with the address to go to (redirects) or of the thing just created (201).
  • Retry-After Response header saying how long to wait before trying again, in seconds or as a date.

Defined in RFC 9110 §15.3.3

203Non-Authoritative InformationOK, but a proxy changed the content.

Success, but a transforming proxy has altered the original 200 response, so it isn’t exactly what the origin server sent.

When you’ll see it
Rarely; some filtering or compressing proxies send it.
If you’re visiting the site
Nothing to do.
If you run the site
Only proxies should send it. If you see it unexpectedly, something between you and the origin is rewriting responses.

Defined in RFC 9110 §15.3.4

204No ContentIt worked; there’s nothing to send back.

Success with an intentionally empty body. A browser stays on the current page.

When you’ll see it
After saving a setting, deleting an item or sending analytics beacons.
If you’re visiting the site
Nothing to do.
If you run the site
Ideal for DELETE and for PUT or PATCH when you don’t return the item. Never include a body; some clients hang waiting for one if Content-Length is wrong.

Defined in RFC 9110 §15.3.5

205Reset ContentDone; clear the form.

Success, and the client should reset the view that sent the request, such as emptying a form for the next entry. No body is allowed.

When you’ll see it
Almost never; browsers largely ignore its meaning.
If you’re visiting the site
Nothing to do.
If you run the site
Prefer 204 and reset the form in your own front-end code.

Defined in RFC 9110 §15.3.6

206Partial ContentHere is the part of the file you asked for.

The server is sending only the byte range the client asked for with a Range header, described by Content-Range.

When you’ll see it
Constantly when streaming video or audio, seeking in a media player, or resuming a download.
If you’re visiting the site
Nothing; it’s how seeking and resuming work.
If you run the site
Static file servers and CDNs handle it. If videos won’t seek in Safari, check your server answers Range requests with 206 and Accept-Ranges: bytes.

Related headers

  • Content-Range Says which part of the file is being sent (bytes 0-1023/5000), or the full size when a range is refused.
  • Range Request header asking for only part of a file, used for resuming downloads and video seeking.
  • Accept-Ranges Response header saying the server can send parts of a file (bytes).

Defined in RFC 9110 §15.3.7

207Multi-StatusSeveral results in one reply (WebDAV).

A WebDAV reply whose XML body holds a separate status for each of several resources, for example when one request touched many files.

When you’ll see it
From WebDAV servers such as Nextcloud and SharePoint, and CalDAV/CardDAV calendar sync.
If you’re visiting the site
Nothing to do.
If you run the site
Read the per-item statuses in the body: some may have failed even though the outer code looks like success.

Defined in RFC 4918 §11.1

208Already ReportedAlready listed earlier in this reply (WebDAV).

Used inside a WebDAV 207 body so a resource reachable by several paths (bindings) is only listed once.

When you’ll see it
Only inside WebDAV multi-status responses.
If you’re visiting the site
Nothing to do.
If you run the site
Only relevant if you implement WebDAV bindings.

Defined in RFC 5842 §7.1

226IM UsedHere is a delta, not the whole thing.

The server answered with the changes since a version the client already has (delta encoding), rather than the full resource.

When you’ll see it
Almost never; very few servers implement RFC 3229.
If you’re visiting the site
Nothing to do.
If you run the site
Safe to ignore unless you build delta-encoding support.

Related headers

  • ETag A fingerprint of the current version, used to check whether a cached copy is still current.

Defined in RFC 3229 §10.4.1

3xx Redirection

Look somewhere else, or use your cached copy.

300Multiple ChoicesThere are several versions; pick one.

The resource has more than one representation (say, different languages or formats) and the client should choose. A preferred one may be given in Location.

When you’ll see it
Rarely; most sites choose for you instead.
If you’re visiting the site
Pick one of the links offered, if the page shows any.
If you run the site
Usually better to choose for the client using Accept headers, or redirect with 302 to the best match.

Related headers

  • Location Response header with the address to go to (redirects) or of the thing just created (201).

Defined in RFC 9110 §15.4.1

301Moved PermanentlyThis address has moved for good.

The resource now lives at the address in Location, permanently. Browsers and search engines remember the move and update links. Clients may change a POST into a GET when following it.

When you’ll see it
When a site moves domain, switches to HTTPS, or renames a page.
If you’re visiting the site
Nothing; your browser follows it. Update your bookmark if you like.
If you run the site
Use it for permanent moves so search ranking passes to the new address. Browsers cache 301s hard, so test with 302 first. For POST or PUT endpoints use 308 so the method is kept.

Related headers

  • Location Response header with the address to go to (redirects) or of the thing just created (201).
  • Cache-Control Rules for how long and where a response may be cached.

Defined in RFC 9110 §15.4.2

302FoundTemporarily somewhere else.

The resource is temporarily at the address in Location; keep using the original address in future. Clients may change POST to GET when following it, and almost all do.

When you’ll see it
After logging in, on short links, and when a page sends you somewhere for now.
If you’re visiting the site
Nothing; your browser follows it.
If you run the site
Fine for temporary redirects of GET requests. To redirect after a form POST to a result page, 303 says exactly that; to keep the method, use 307.

Related headers

  • Location Response header with the address to go to (redirects) or of the thing just created (201).

Defined in RFC 9110 §15.4.3

303See OtherGo and GET the result over there.

The server points to another address for the result of the request, and the client should fetch it with GET whatever method it used.

When you’ll see it
After submitting a form, so refreshing the result page doesn’t resubmit (the Post/Redirect/Get pattern).
If you’re visiting the site
Nothing; your browser follows it.
If you run the site
Use it after a successful POST to send the user to a confirmation or the new item’s page.

Related headers

  • Location Response header with the address to go to (redirects) or of the thing just created (201).

Defined in RFC 9110 §15.4.4

304Not ModifiedYour cached copy is still current.

Reply to a conditional GET or HEAD: the resource hasn’t changed since the version the client has, so the client should use its cached copy. No body is sent.

When you’ll see it
In the Network tab for files your browser already has, when it checks with If-None-Match or If-Modified-Since.
If you’re visiting the site
Nothing; it makes pages load faster.
If you run the site
Send ETag or Last-Modified and your framework usually handles 304s. Never put a body on a 304, and include the same caching headers a 200 would have.

Related headers

  • ETag A fingerprint of the current version, used to check whether a cached copy is still current.
  • Last-Modified When the resource last changed, also used to check cached copies.
  • If-None-Match Request header: “only send it if the fingerprint has changed” — leads to 304 if not.
  • If-Modified-Since Request header: “only send it if it changed after this date” — leads to 304 if not.
  • Cache-Control Rules for how long and where a response may be cached.

Defined in RFC 9110 §15.4.5

305Use ProxyDeprecated: use a proxy.Deprecated

Once told the client to repeat the request through a proxy named by the server. It was deprecated for security reasons and browsers ignore it.

When you’ll see it
Effectively never.
If you’re visiting the site
Nothing; browsers won’t act on it.
If you run the site
Don’t use it.

Defined in RFC 9110 §15.4.6

306(Unused)Reserved; no longer used.Unused

Used in an early draft (“Switch Proxy”) and now reserved so it is never given another meaning.

When you’ll see it
Never in practice.
If you’re visiting the site
Nothing.
If you run the site
Don’t use it.

Defined in RFC 9110 §15.4.7

307Temporary RedirectTemporarily elsewhere; repeat the same request there.

Like 302, but the client must not change the method or body: a POST is re-sent as a POST to the new address. Browsers also show 307 internally when HSTS upgrades http:// to https://.

When you’ll see it
In API gateways and load balancers, and as an “Internal Redirect” to HTTPS in Chrome’s Network tab.
If you’re visiting the site
Nothing; your browser follows it.
If you run the site
Use it for temporary redirects where the method matters, such as moving an API endpoint for a while.

Related headers

  • Location Response header with the address to go to (redirects) or of the thing just created (201).
  • Strict-Transport-Security Tells browsers to use HTTPS only for this site from now on.

Defined in RFC 9110 §15.4.8

308Permanent RedirectMoved for good; repeat the same request there.

Like 301, but the method and body must be kept: a POST stays a POST. Cached and remembered like a 301.

When you’ll see it
On sites and APIs that moved permanently, and some hosts use it for trailing-slash and HTTPS redirects.
If you’re visiting the site
Nothing; your browser follows it.
If you run the site
The safest permanent redirect for APIs. Very old clients may not know it; for plain web pages 301 is equally fine.

Related headers

  • Location Response header with the address to go to (redirects) or of the thing just created (201).

Defined in RFC 9110 §15.4.9

4xx Client error

Something about the request is wrong.

400Bad RequestThe server couldn’t understand the request.

The request is broken in a way the server won’t process: malformed syntax, invalid framing, a bad JSON body, or a value it can’t make sense of.

When you’ll see it
After a typo in a web address, a corrupted cookie, a form sent with missing fields, or a bug in an app.
If you’re visiting the site
Check the address for typos, reload, or clear this site’s cookies — an oversized or damaged cookie is a common cause.
If you run the site
Say what was wrong in the body (which field, and why). For a body that parses but fails your rules, many APIs use 422 instead.

Related headers

  • Content-Type The format of the body, such as application/json.

Defined in RFC 9110 §15.5.1

401UnauthorizedYou need to log in (or your login didn’t work).

Despite the name, this means unauthenticated: no valid credentials were sent. The response must include WWW-Authenticate saying how to log in.

When you’ll see it
When a session has expired, a password or API token is wrong, or a browser shows its own login pop-up.
If you’re visiting the site
Log in again. If you’re already logged in, log out and back in, as your session may have expired.
If you run the site
Send WWW-Authenticate (e.g. Bearer). If the user is logged in but not allowed, that’s 403, not 401.

Related headers

  • WWW-Authenticate Response header naming the login scheme the server accepts, such as Basic or Bearer.
  • Authorization Request header carrying the credentials, such as a token.

Defined in RFC 9110 §15.5.2

402Payment RequiredReserved for future use (payment).

Reserved by the HTTP standard with no agreed meaning. Some services use it for unpaid accounts, exceeded plans or failed card payments.

When you’ll see it
From some APIs and hosting platforms when a bill is unpaid or a quota needs a paid plan.
If you’re visiting the site
Check the account’s billing or subscription.
If you run the site
If you use it, explain exactly what payment is needed in the body; clients won’t know what it means otherwise.

Defined in RFC 9110 §15.5.3

403ForbiddenYou’re not allowed to see this.

The server understood the request and knows (or doesn’t need) who you are, but refuses it. Logging in again won’t help.

When you’ll see it
On admin pages, private files, folders without an index page, or when a firewall or bot protection blocks you.
If you’re visiting the site
Check you’re in the right account. If a security check blocked you, turning off a VPN or waiting a while sometimes helps.
If you run the site
Use it for “logged in but not permitted”. To hide that something exists at all, 404 is allowed instead. Check file permissions and WAF rules when it’s unexpected.

Defined in RFC 9110 §15.5.4

404Not FoundThere’s nothing at this address.

The server has nothing at this address, or won’t say whether it does. It doesn’t say whether the absence is temporary or permanent.

When you’ll see it
After a mistyped address, a deleted page, or an old link to a moved page.
If you’re visiting the site
Check the spelling, remove the end of the address to go up a level, or use the site’s search.
If you run the site
Make a helpful 404 page with search and links. Redirect moved pages with 301; use 410 for content deliberately removed for good.

Defined in RFC 9110 §15.5.5

405Method Not AllowedThis address doesn’t accept that kind of request.

The resource exists but doesn’t support the method used (for example POST to a read-only page). The response must list allowed methods in Allow.

When you’ll see it
When a form posts to the wrong address, or an API call uses GET instead of POST.
If you’re visiting the site
Go back and try again from the site’s own pages.
If you run the site
Send Allow with the supported methods. Check form action URLs, and that proxies or static hosts aren’t rejecting POST.

Related headers

  • Allow Response header listing the methods this address accepts, such as GET, POST.

Defined in RFC 9110 §15.5.6

406Not AcceptableCan’t send it in a format you accept.

The server can’t produce a response matching the client’s Accept headers (format, language or encoding).

When you’ll see it
From APIs when a client asks only for XML but the API speaks JSON, and from some security filters.
If you’re visiting the site
Try another browser; strict security software can trigger it.
If you run the site
Most APIs ignore narrow Accept headers and send their default format; only return 406 when you truly can’t serve anything useful.

Related headers

  • Accept Request header listing formats the client can take, such as application/json.
  • Accept-Encoding Request header listing compression the client can take, such as gzip or br.
  • Vary Lists request headers that change the response, so caches keep separate copies.

Defined in RFC 9110 §15.5.7

407Proxy Authentication RequiredLog in to the proxy first.

Like 401, but for a proxy between you and the site: it needs credentials before it will pass the request on.

When you’ll see it
On office, school or hotel networks that route traffic through a login-protected proxy.
If you’re visiting the site
Enter your network login, or ask the network’s IT team.
If you run the site
Configure your HTTP client with the proxy’s credentials (Proxy-Authorization).

Related headers

  • Proxy-Authenticate Response header from a proxy naming the login scheme it accepts.
  • Proxy-Authorization Request header carrying credentials for a proxy.

Defined in RFC 9110 §15.5.8

408Request TimeoutYou took too long to send the request.

The server didn’t receive a complete request in the time it was willing to wait and is closing the connection.

When you’ll see it
On very slow or unstable connections, and sometimes from browsers’ idle pre-opened connections.
If you’re visiting the site
Reload. If it keeps happening, check your connection.
If you run the site
Usually harmless and logged for idle connections. Raise client body timeouts if large uploads on slow links fail.

Related headers

  • Connection Controls the connection itself; must include “upgrade” when switching protocols.

Defined in RFC 9110 §15.5.9

409ConflictClashes with the current state of the data.

The request can’t be done because it conflicts with the resource’s current state, such as an edit based on an old version or a name that’s already taken.

When you’ll see it
When two people edit the same thing, or you sign up with a username that exists.
If you’re visiting the site
Reload to get the latest version, then make your change again.
If you run the site
Explain the conflict in the body so the client can resolve it. For version checks with If-Match, 412 is the precise code.

Defined in RFC 9110 §15.5.10

410GoneRemoved on purpose, and not coming back.

The resource used to exist, has been deliberately removed, and no forwarding address is known. Unlike 404, this is known to be permanent.

When you’ll see it
For deleted accounts, expired offers or retired API versions.
If you’re visiting the site
The page is gone; search the site for something similar.
If you run the site
Use it to make search engines drop removed pages faster than a 404 would.

Defined in RFC 9110 §15.5.11

411Length RequiredSay how big the body is.

The server refuses a request without a Content-Length header.

When you’ll see it
From some servers when a client streams an upload without giving its size.
If you’re visiting the site
Nothing you can change; try another app or browser.
If you run the site
Send Content-Length, or check the server accepts chunked uploads.

Related headers

  • Content-Length The size of the body in bytes.

Defined in RFC 9110 §15.5.12

412Precondition FailedThe version you expected has changed.

A condition in the request headers, such as If-Match or If-Unmodified-Since, wasn’t true, so the change wasn’t made. It prevents overwriting someone else’s edit.

When you’ll see it
In APIs and cloud storage when saving over a file that changed since you loaded it.
If you’re visiting the site
Reload and try again.
If you run the site
Fetch the latest version and its ETag, merge the change, and retry with the new If-Match.

Related headers

  • If-Match Request header: “only change it if it is still this version” — leads to 412 if not.
  • If-Unmodified-Since Request header: “only change it if unchanged since this date” — leads to 412 if not.
  • ETag A fingerprint of the current version, used to check whether a cached copy is still current.

Defined in RFC 9110 §15.5.13

413Content Too LargeThe upload is bigger than the server allows.

The request body is larger than the server is willing to take. Formerly called “Payload Too Large” and “Request Entity Too Large”.

When you’ll see it
When uploading a big photo or video to a site with a size limit.
If you’re visiting the site
Make the file smaller (compress or resize it) and try again.
If you run the site
Raise the limit where it bites: Nginx client_max_body_size, PHP upload_max_filesize and post_max_size, or your framework’s body-size option. If the limit is temporary, add Retry-After.

Related headers

  • Retry-After Response header saying how long to wait before trying again, in seconds or as a date.
  • Content-Length The size of the body in bytes.

Defined in RFC 9110 §15.5.14

414URI Too LongThe web address is too long.

The target address is longer than the server will handle.

When you’ll see it
When a search or form puts huge amounts of data into the address, or a redirect loop keeps adding to it.
If you’re visiting the site
Shorten the address or start again from the home page.
If you run the site
Send large data in a POST body instead of query strings, and check for redirect loops that append parameters.

Defined in RFC 9110 §15.5.15

415Unsupported Media TypeThe server won’t take that format.

The body’s format (Content-Type) or encoding isn’t supported for this request.

When you’ll see it
When an app sends form data to a JSON API, or uploads a file type the site doesn’t accept.
If you’re visiting the site
Try a different file type, such as JPG instead of HEIC.
If you run the site
Check Content-Type matches the body (application/json for JSON). Tell clients what you accept with Accept-Post or Accept-Encoding.

Related headers

  • Content-Type The format of the body, such as application/json.
  • Accept-Post Response header listing body formats a POST may use.
  • Accept-Encoding Request header listing compression the client can take, such as gzip or br.

Defined in RFC 9110 §15.5.16

416Range Not SatisfiableThat part of the file doesn’t exist.

The byte range asked for in the Range header lies outside the file, for example resuming a download past its end.

When you’ll see it
When resuming a download whose file has changed or shrunk, or from buggy video players.
If you’re visiting the site
Delete the partial download and start it again.
If you run the site
Send Content-Range: bytes */<full size> so the client can correct itself.

Related headers

  • Range Request header asking for only part of a file, used for resuming downloads and video seeking.
  • Content-Range Says which part of the file is being sent (bytes 0-1023/5000), or the full size when a range is refused.

Defined in RFC 9110 §15.5.17

417Expectation FailedCan’t meet the Expect header.

The server can’t meet what the client asked for in its Expect header (usually 100-continue).

When you’ll see it
From some proxies that don’t support Expect: 100-continue.
If you’re visiting the site
Nothing you can change.
If you run the site
Retry without the Expect header (in curl: -H "Expect:").

Related headers

  • Expect Request header; “100-continue” asks the server to approve the body before it is sent.

Defined in RFC 9110 §15.5.18

418I’m a teapotA joke: the teapot refuses to brew coffee.Unofficial

From the 1998 April Fools’ “Hyper Text Coffee Pot Control Protocol”. RFC 9110 lists 418 as unused and reserved, so it will never get a real meaning, partly because so many programs already know the joke.

When you’ll see it
As an Easter egg on some sites, and occasionally as a cheeky reply to bots.
If you’re visiting the site
Enjoy the joke.
If you run the site
Fine for fun, but don’t use it for real errors; clients won’t know what to do with it.

Source: RFC 2324 (April Fools’ joke); reserved in RFC 9110 §15.5.19

419Page ExpiredLaravel: the form’s security token expired.Unofficial · Laravel

Laravel sends this when a form’s CSRF token (the hidden code that proves the form came from the site) is missing or has expired.

When you’ll see it
After leaving a form open for a long time, or when cookies are blocked, on Laravel sites.
If you’re visiting the site
Reload the page and submit the form again.
If you run the site
Include @csrf in forms, send the X-CSRF-TOKEN header with AJAX requests, and check the session cookie domain and lifetime.

Source: Laravel (PHP framework)

420Enhance Your CalmOld Twitter API rate limit.Unofficial · Twitter

Twitter’s old API used it for rate limiting before the standard 429 existed. Spring Framework once used 420 for “Method Failure”.

When you’ll see it
Only in very old integrations and tutorials.
If you’re visiting the site
Wait and try again.
If you run the site
Use 429 Too Many Requests instead.

Source: Twitter API v1 (retired)

421Misdirected RequestThis server can’t answer for that site.

The request reached a server that isn’t set up to answer for that host name, often because an HTTP/2 connection was reused across sites that share an IP address or certificate.

When you’ll see it
After certificate or virtual-host changes, on CDNs, and with shared hosting.
If you’re visiting the site
Reload; if it persists, restart the browser to open fresh connections.
If you run the site
Check each host has a matching server block and certificate. In Nginx, make sure TLS settings for sites sharing an IP are compatible.

Defined in RFC 9110 §15.5.20

422Unprocessable ContentUnderstood, but the data isn’t valid.

The request is well-formed and in a supported format, but its contents can’t be processed — typically validation errors like a missing required field or an invalid email. Formerly “Unprocessable Entity”.

When you’ll see it
From APIs (Rails, Laravel, FastAPI) when a form fails validation.
If you’re visiting the site
Check the form for highlighted errors and correct them.
If you run the site
Return a list of field errors in the body so the front end can show them next to each field.

Related headers

  • Content-Type The format of the body, such as application/json.

Defined in RFC 9110 §15.5.21

423LockedThe file is locked (WebDAV).

The resource is locked, usually because someone else has the file open for editing.

When you’ll see it
In WebDAV and online file storage when a document is open elsewhere.
If you’re visiting the site
Wait until the other person closes the file, or ask them to.
If you run the site
Release stale locks, and tell the user who holds the lock if you know.

Defined in RFC 4918 §11.3

424Failed DependencyFailed because an earlier step failed (WebDAV).

The action wasn’t done because another action it depended on, in the same request, failed.

When you’ll see it
Inside WebDAV multi-status replies.
If you’re visiting the site
Nothing; try the whole action again.
If you run the site
Look for the first failure in the batch; this code marks the knock-on effects.

Defined in RFC 4918 §11.4

425Too EarlyWon’t risk a replayed request.

The server won’t process a request sent in TLS early data (0-RTT), because an attacker could replay it. The client should retry after the handshake completes.

When you’ll see it
Rarely, from CDNs that enable TLS 1.3 0-RTT.
If you’re visiting the site
Nothing; browsers retry automatically.
If you run the site
Return it for non-idempotent requests marked with Early-Data: 1, or turn off 0-RTT for them.

Related headers

  • Early-Data Added by a proxy when the request arrived in TLS early data (0-RTT), which could be replayed.

Defined in RFC 8470 §5.2

426Upgrade RequiredSwitch to a newer protocol first.

The server refuses the request over the current protocol but would accept it after an upgrade, named in the Upgrade header.

When you’ll see it
From WebSocket-only endpoints opened in a normal browser tab, and some services requiring newer protocols.
If you’re visiting the site
Update your app or browser.
If you run the site
Send Upgrade (and Connection: Upgrade) naming the protocol needed.

Related headers

  • Upgrade Names the protocol to switch to, such as websocket.
  • Connection Controls the connection itself; must include “upgrade” when switching protocols.

Defined in RFC 9110 §15.5.22

428Precondition RequiredMake this a conditional request.

The server requires the request to be conditional (If-Match) to prevent lost updates when several people edit the same thing.

When you’ll see it
From APIs that insist on optimistic locking.
If you’re visiting the site
Nothing; it’s for apps.
If you run the site
Fetch the resource, read its ETag, and send it back in If-Match when saving.

Related headers

  • If-Match Request header: “only change it if it is still this version” — leads to 412 if not.
  • ETag A fingerprint of the current version, used to check whether a cached copy is still current.

Defined in RFC 6585 §3

429Too Many RequestsSlow down — too many requests.

The client sent too many requests in a given time (rate limiting). Retry-After may say how long to wait.

When you’ll see it
From APIs when a quota is hit, after many login attempts, or when refreshing a page rapidly.
If you’re visiting the site
Wait a minute or two before trying again.
If you run the site
Send Retry-After. As a client, back off exponentially and respect Retry-After instead of retrying at once.

Related headers

  • Retry-After Response header saying how long to wait before trying again, in seconds or as a date.

Defined in RFC 6585 §4

431Request Header Fields Too LargeThe request headers (often cookies) are too big.

One header, or all of them together, is larger than the server allows. Huge cookies are the usual cause.

When you’ll see it
On sites that set many or large cookies, especially during local development on localhost.
If you’re visiting the site
Clear cookies for this site, then reload.
If you run the site
Trim cookies, or raise limits (Node’s --max-http-header-size, Nginx large_client_header_buffers).

Defined in RFC 6585 §5

444No ResponseNginx closed the connection without replying.Unofficial · Nginx

An Nginx instruction rather than a real reply: it closes the connection without sending anything. It appears only in Nginx’s logs.

When you’ll see it
Never as a page; the browser reports an empty response or a dropped connection.
If you’re visiting the site
The site is refusing your request; it may be blocking your network.
If you run the site
Handy for dropping obvious bot traffic or requests for unknown host names (return 444; in a default server block).

Source: Nginx

451Unavailable For Legal ReasonsBlocked for legal reasons.

The server can’t show this because of a legal demand, such as a court order, government censorship or copyright takedown. The number nods to the novel Fahrenheit 451.

When you’ll see it
For content blocked in certain countries, or removed after legal action.
If you’re visiting the site
The content isn’t available where you are.
If you run the site
Explain the reason in the body, and say who made the demand in a Link header with rel="blocked-by" if you can.

Related headers

  • Link Points to related resources; with 103 it tells the browser what to preload early.

Defined in RFC 7725 §3

494Request Header Too LargeNginx: request headers or cookies too big.Unofficial · Nginx

Nginx’s internal code for headers or cookies larger than its buffers. Visitors see “400 Bad Request – Request Header Or Cookie Too Large”.

When you’ll see it
On sites that set lots of cookies.
If you’re visiting the site
Clear this site’s cookies and reload.
If you run the site
Shrink cookies, or raise large_client_header_buffers.

Nginx uses this number internally and in its logs; visitors are shown a 400 page with a specific message instead.

Source: Nginx

495SSL Certificate ErrorNginx: the client certificate is invalid.Unofficial · Nginx

Used when a site requires client certificates (mutual TLS) and the one presented isn’t valid.

When you’ll see it
On company or government systems that log you in with a certificate.
If you’re visiting the site
Check your certificate or smart card is installed and current.
If you run the site
Check ssl_client_certificate and ssl_verify_client settings and the client certificate’s chain.

Nginx uses this number internally and in its logs; visitors are shown a 400 page with a specific message instead.

Source: Nginx

496SSL Certificate RequiredNginx: a client certificate is required.Unofficial · Nginx

The site requires a client certificate and none was sent.

When you’ll see it
On systems that use certificate logins, from a device without the certificate.
If you’re visiting the site
Use the device or browser with your certificate installed.
If you run the site
Expected when ssl_verify_client is on and the client sent no certificate.

Nginx uses this number internally and in its logs; visitors are shown a 400 page with a specific message instead.

Source: Nginx

497HTTP Request Sent to HTTPS PortNginx: plain HTTP sent to the HTTPS port.Unofficial · Nginx

A plain http:// request arrived on a port that expects HTTPS.

When you’ll see it
When typing http://site:443, or after a misconfigured redirect.
If you’re visiting the site
Use https:// at the start of the address.
If you run the site
Add error_page 497 =301 https://$host$request_uri; to redirect such requests.

Nginx uses this number internally and in its logs; visitors are shown a 400 page with a specific message instead.

Source: Nginx

499Client Closed RequestNginx: the visitor gave up before the reply.Unofficial · Nginx

Logged by Nginx when the client closed the connection before the server answered. No response is ever delivered.

When you’ll see it
Only in server logs, when users close the tab, press Stop, or an app times out.
If you’re visiting the site
Nothing; you won’t see it.
If you run the site
Many 499s point to slow responses, or clients and load balancers with timeouts shorter than your server’s.

Only written to Nginx’s logs; it is never sent, so there is nothing to set.

Source: Nginx

5xx Server error

The server failed to handle a valid request.

500Internal Server ErrorSomething broke on the server.

A catch-all: the server hit an unexpected condition and couldn’t finish the request. The fault is on the server side, not with the request.

When you’ll see it
When a website’s code crashes, a database query fails, or a config file has a mistake.
If you’re visiting the site
Reload after a minute. If it persists, the site’s owner has to fix it.
If you run the site
Check the server error log for the stack trace. Show users a friendly error page and never leak stack traces in production.

Defined in RFC 9110 §15.6.1

501Not ImplementedThe server doesn’t support this at all.

The server doesn’t recognise or support the request method for any resource. (405 means “not for this address”; 501 means “not anywhere”.)

When you’ll see it
When a client uses an unusual method such as PROPFIND on a server that doesn’t do WebDAV.
If you’re visiting the site
Nothing you can change.
If you run the site
Use it for methods the server doesn’t support at all; for features still to be built, a 404 or 405 is usually clearer.

Defined in RFC 9110 §15.6.2

502Bad GatewayThe server behind the gateway sent a bad reply.

A gateway or proxy (Nginx, a load balancer, a CDN) got an invalid response — or none — from the server behind it.

When you’ll see it
When an app server has crashed or is restarting behind Nginx, or a CDN can’t talk to the origin.
If you’re visiting the site
Wait a minute and reload. It’s usually brief.
If you run the site
Check the upstream app is running and listening on the port the proxy expects, and read the proxy’s error log (“connection refused”, “upstream prematurely closed”).

Defined in RFC 9110 §15.6.3

503Service UnavailableTemporarily down or overloaded.

The server can’t handle the request right now, because of maintenance or overload, and expects to recover. Retry-After can say when.

When you’ll see it
During maintenance, traffic spikes, or when a host suspends an over-limit site.
If you’re visiting the site
Try again in a few minutes.
If you run the site
Use it for planned maintenance with Retry-After; search engines treat a short 503 as temporary and won’t drop your pages.

Related headers

  • Retry-After Response header saying how long to wait before trying again, in seconds or as a date.

Defined in RFC 9110 §15.6.4

504Gateway TimeoutThe server behind the gateway took too long.

A gateway or proxy didn’t get a reply in time from the server behind it.

When you’ll see it
When a slow page, report or upload takes longer than the proxy’s time limit.
If you’re visiting the site
Reload after a short wait; the server may be busy.
If you run the site
Speed up the slow request or move it to a background job (202), or raise the proxy timeout (Nginx proxy_read_timeout).

Defined in RFC 9110 §15.6.5

505HTTP Version Not SupportedThat HTTP version isn’t supported.

The server refuses the major HTTP version used in the request.

When you’ll see it
Very rarely, with misbehaving clients or misconfigured proxies.
If you’re visiting the site
Nothing; try another browser.
If you run the site
Check the client isn’t sending a malformed request line.

Defined in RFC 9110 §15.6.6

506Variant Also NegotiatesServer misconfiguration in content negotiation.

A configuration error in transparent content negotiation: the chosen variant is itself set up to negotiate, creating a loop.

When you’ll see it
Almost never.
If you’re visiting the site
Nothing; the site owner must fix it.
If you run the site
Check content-negotiation settings (such as Apache type maps).

Defined in RFC 2295 §8.1

507Insufficient StorageThe server is out of space.

The server can’t store what’s needed to complete the request. Defined for WebDAV but used more widely.

When you’ll see it
When a cloud drive or WebDAV server is full.
If you’re visiting the site
Free some space in your account, or upgrade it.
If you run the site
Check disk space and quotas on the server.

Defined in RFC 4918 §11.5

508Loop DetectedStopped an endless loop.

The server stopped an operation because it found an infinite loop, originally in WebDAV bindings. Some hosts also use it when a site hits its process limits.

When you’ll see it
Rarely; on some shared hosts it means the site exceeded its resource limits.
If you’re visiting the site
Try later.
If you run the site
Look for loops in WebDAV bindings, or for scripts calling themselves through HTTP.

Defined in RFC 5842 §7.2

509Bandwidth Limit ExceededThe site used up its hosting bandwidth.Unofficial · Apache

Shared hosting (often cPanel) sends it when a site exceeds its monthly data allowance.

When you’ll see it
On small sites after a traffic spike.
If you’re visiting the site
Try later, maybe next month; the owner needs to raise the limit.
If you run the site
Upgrade the hosting plan, add a CDN, or shrink large files.

Source: Apache / cPanel hosting

510Not ExtendedA required extension wasn’t declared (historic).Historic

From the experimental HTTP Extension Framework: the request needed extensions the client didn’t declare. That framework is now historic and unused.

When you’ll see it
Effectively never.
If you’re visiting the site
Nothing.
If you run the site
Don’t use it.

Defined in RFC 2774 §7

511Network Authentication RequiredLog in to the network (Wi-Fi) first.

Sent by a captive portal (hotel, café or airport Wi-Fi) that intercepts traffic until you sign in or accept terms.

When you’ll see it
On public Wi-Fi before you’ve signed in.
If you’re visiting the site
Open any website to get the Wi-Fi sign-in page, or reconnect to the network.
If you run the site
Only network gateways should send it — never an origin website.

Defined in RFC 6585 §6

520Web Server Returned an Unknown ErrorCloudflare: the origin replied with something odd.Unofficial · Cloudflare

Cloudflare reached the site’s own server but got an empty, unknown or invalid response.

When you’ll see it
On Cloudflare sites when the origin crashes, resets connections or sends oversized headers.
If you’re visiting the site
Reload after a minute.
If you run the site
Check the origin’s error logs, header sizes (Cloudflare limits them) and that it isn’t resetting connections.

Cloudflare generates this at its edge; your own server never sends it.

Source: Cloudflare

521Web Server Is DownCloudflare: the origin refused the connection.Unofficial · Cloudflare

Cloudflare couldn’t connect because the origin server refused it — the web server is off or a firewall is blocking Cloudflare.

When you’ll see it
When a Cloudflare site’s server is down.
If you’re visiting the site
Try later.
If you run the site
Start the web server, and allow Cloudflare’s IP ranges through the firewall.

Cloudflare generates this at its edge; your own server never sends it.

Source: Cloudflare

522Connection Timed OutCloudflare: the origin didn’t answer the connection.Unofficial · Cloudflare

Cloudflare’s attempt to open a connection to the origin timed out.

When you’ll see it
When the origin is overloaded, offline or silently dropping Cloudflare’s traffic.
If you’re visiting the site
Try later.
If you run the site
Check the server is up, not overloaded, and that firewalls or rate limits aren’t dropping Cloudflare IPs.

Cloudflare generates this at its edge; your own server never sends it.

Source: Cloudflare

523Origin Is UnreachableCloudflare: can’t find a route to the origin.Unofficial · Cloudflare

Cloudflare couldn’t reach the origin at all, often because the DNS record points to the wrong IP address.

When you’ll see it
After moving servers without updating DNS.
If you’re visiting the site
Try later.
If you run the site
Check the DNS records in Cloudflare point to the right server.

Cloudflare generates this at its edge; your own server never sends it.

Source: Cloudflare

524A Timeout OccurredCloudflare: connected, but the reply took too long.Unofficial · Cloudflare

Cloudflare connected to the origin but got no HTTP response within its time limit (100 seconds by default).

When you’ll see it
On long-running pages, exports and reports behind Cloudflare.
If you’re visiting the site
Try again; the task may be too heavy right now.
If you run the site
Move long work to a background job and poll for the result.

Cloudflare generates this at its edge; your own server never sends it.

Source: Cloudflare

525SSL Handshake FailedCloudflare: HTTPS to the origin failed.Unofficial · Cloudflare

Cloudflare couldn’t complete the secure (TLS) handshake with the origin.

When you’ll see it
With Full or Strict SSL mode when the origin has no working certificate on port 443.
If you’re visiting the site
Try later.
If you run the site
Install a valid certificate on the origin (a Cloudflare Origin CA certificate works) and check the TLS settings match.

Cloudflare generates this at its edge; your own server never sends it.

Source: Cloudflare

526Invalid SSL CertificateCloudflare: the origin’s certificate isn’t valid.Unofficial · Cloudflare

In Full (Strict) mode, Cloudflare rejected the origin’s certificate as expired, self-signed or for the wrong host name.

When you’ll see it
When an origin certificate expires.
If you’re visiting the site
Try later.
If you run the site
Renew or replace the origin certificate so it is valid for the host name.

Cloudflare generates this at its edge; your own server never sends it.

Source: Cloudflare

530Error With a 1xxx CodeCloudflare: shown with a 1xxx error.Unofficial · Cloudflare

Cloudflare returns 530 together with a 1xxx error page, most often 1016 (origin DNS error), when it can’t resolve or reach the origin.

When you’ll see it
On Cloudflare sites with broken DNS or tunnels.
If you’re visiting the site
Try later.
If you run the site
Read the 1xxx code on the error page; for 1016 check the origin’s DNS record or Cloudflare Tunnel.

Cloudflare generates this at its edge; your own server never sends it.

Source: Cloudflare

About this tool

This is a searchable guide to HTTP status codes, the three-digit numbers a web server sends back with every page, image and API call. It covers every code in the official IANA registry, checked against RFC 9110 (the current HTTP standard) and the newer RFCs that added codes such as 429 and 451, plus a clearly labelled set of unofficial codes you will meet in real life: Nginx’s 444 and 499, Laravel’s 419, and Cloudflare’s 520 to 530.

Each code opens to the same five parts: what it means in plain English, when you are likely to see it, what to do if you are just visiting the site, what to do if you run the site, and which headers go with it, such as Retry-After for 429 and 503 or Location for redirects. Where it makes sense, there is ready-to-copy code for sending that status from Express, Flask, PHP and Nginx.

It is written for developers who need the exact difference between 301 and 308, and for everyone else who just hit a 403 and wants to know whose fault it is.

How to use HTTP Status Codes

  1. Type a number or a few words into the search box, such as 404, “too many” or “cookie”. A three-digit match opens by itself.
  2. Or narrow the list with the buttons: 1xx Information, 2xx Success, 3xx Redirection, 4xx Client error, 5xx Server error, or Unofficial.
  3. Open a code to read what it means, when you will see it, and what to do as a visitor or as the site’s developer.
  4. Pick Express, Flask, PHP or Nginx above the code sample and press “Copy”. Your choice is remembered for every code.
  5. Press “Copy link” to share a direct link to that code. Adding #404 to this page’s address opens 404 straight away.
Example

Searching “slow” finds 408 Request Timeout, 429 Too Many Requests and 504 Gateway Timeout. Opening 429 shows the Retry-After header and, in Express, res.set('Retry-After', '120') followed by res.status(429).

Features

  • Every registered code from 100 Continue to 511 Network Authentication Required, including the WebDAV codes (207, 423, 507) and historic or deprecated ones, clearly marked.
  • Common unofficial codes labelled with who uses them: 418, 419, 420, 444, 494–497, 499, 509 and Cloudflare’s 520–526 and 530.
  • Plain-English meaning, when you will see it, and separate advice for visitors and for developers on every code.
  • Related headers with a one-line explanation each, such as WWW-Authenticate, Allow, ETag and Content-Range.
  • Copyable code for Express, Flask, PHP and Nginx, with the right headers and redirect syntax for each code.
  • Search by number, by class (type 4xx), or by words found anywhere in a code’s description.
  • Deep links: every code has its own address, like #404, that opens and highlights it.
  • The source for every official code, down to the RFC section.

Tips and good to know

  • 401 means “we don’t know who you are” and 403 means “we know, and the answer is no”. Logging in again only fixes a 401.
  • Use 301 or 308 for permanent moves and 302 or 307 for temporary ones. The 307 and 308 pair keep the request method, so a POST stays a POST.
  • A 502, 503 or 504 usually comes from a proxy or load balancer in front of the app, so look in the proxy’s logs as well as the app’s.
  • Codes in the 520s with a Cloudflare page mean Cloudflare couldn’t get a good answer from the site’s own server. The site owner, not the visitor, has to fix them.
  • Never send 200 with an error message inside. Browsers, caches, search engines and monitoring tools all trust the number.

Frequently asked questions

Does this page send anything about my searches anywhere?

No. The whole list is part of the page, and searching, filtering and copying all happen in your browser. Nothing you type is sent to AroraTools or anyone else.

Is it free, and can I use the code samples in my projects?

Yes to both. The guide is free with no sign-up, and the short code samples are simple enough to copy into any project.

Does it work on my phone and offline?

Yes. It works in any modern browser on phones, tablets and computers. Once the page has loaded, searching and opening codes keep working without a connection.

What is the difference between 404 and 410?

404 Not Found says nothing is at the address, without saying whether that is permanent. 410 Gone says the page existed and was removed on purpose for good, which helps search engines drop it sooner.

Is 418 I’m a teapot a real status code?

It began as an April Fools’ joke in 1998. RFC 9110 now lists 418 as reserved and unused so it never gets a real meaning, which is why it is marked unofficial here.

Why do I see a 499 in my logs that no one ever received?

499 is written by Nginx when the visitor closed the connection before the server replied, for example by closing the tab. It is never sent to anyone; many of them usually mean some responses are slow.

Page last reviewed