Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

HTTP status codes are three-digit response codes from 100 through 599. Their first digit tells you the broad result: informational (1xx), successful (2xx), redirection (3xx), client error (4xx), or server error (5xx). To interpret a particular response, check the code together with the request method and relevant headers—especially Location, WWW-Authenticate, Allow, and Retry-After.

How to read an HTTP status code

A status code describes the result of a request and the semantics of the response, including whether the request succeeded and what content is enclosed, if any. RFC 9110 defines valid HTTP status codes as integers from 100 through 599. The first digit identifies the class; the last two digits do not have a class-categorization role.

Class Meaning Practical reading
1xx Informational An interim response; processing continues before a final response.
2xx Successful The request was received, understood, and accepted; check the method and headers to know exactly what succeeded.
3xx Redirection Further action is needed to complete the request, often by following a redirect or validating a cached response.
4xx Client error The request cannot be fulfilled as sent, or the server refuses it for a request-related reason.
5xx Server error A server or intermediary failed to fulfill an apparently valid request.

A status code is not a complete diagnosis. A 404, for example, can mean that no current representation is available or that the server is not willing to disclose that one exists. Read the response headers and body, and consider whether a proxy, gateway, cache, or origin produced the response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

1xx informational responses

A 1xx response is interim: it ends at the header section and is followed by a final response. HTTP/1.0 servers must not send 1xx responses to HTTP/1.0 clients.

Code Meaning What to know
100 Continue The server received the initial request portion and intends to continue once it receives the rest. Commonly associated with the Expect: 100-continue request header.
101 Switching Protocols The server agrees to change the application protocol. Sent in response to an Upgrade request.
102 Processing A WebDAV processing update. A registered extension.
103 Early Hints The server sends preliminary response headers before its final response. It is not the final result of the request.
104 Upload Resumption Supported A temporary registered extension related to upload resumption. IANA records it as registered on 2024-11-13, with the extension registered on 2025-09-15 and an expiry date of 2026-11-13. Its temporary status means implementations should check the current IANA registry rather than assume permanence.

2xx successful responses

A 2xx response indicates success at the HTTP level, but the client’s next step depends on the method and response headers. An accepted request is not necessarily a completed job, and a successful response does not always contain a body.

Code Meaning Practical interpretation
200 OK The request succeeded. Its precise meaning depends on the request method.
201 Created The request succeeded and created a resource. A Location header commonly identifies the new resource.
202 Accepted The request was accepted for processing. Processing may not be complete when the response arrives; the client may need to check the application’s documented follow-up mechanism.
203 Non-Authoritative Information The response metadata differs from the origin server’s representation. Do not assume the metadata is identical to what the origin supplied.
204 No Content The request succeeded with no response content. A client should not expect a response body.
206 Partial Content The server is returning a requested range of a representation. Interpret it in the context of the range request.
207 Multi-Status A specialized registered response. Associated with WebDAV.
208 Already Reported A specialized registered response. Associated with WebDAV.
226 IM Used A specialized registered response. Used for instance manipulations.

Do not treat every 2xx response as interchangeable. In particular, distinguish a completed result (such as 200) from an accepted-for-processing result (202), and from a success that deliberately carries no content (204).

3xx redirection and cache responses

For redirects, ask whether the destination is temporary or permanent and whether the original request method and body must be preserved. Those details matter for form submissions, API calls, and migrations. A 304 is different: it tells a client using conditional request headers that its cached representation remains valid; it does not provide a replacement body.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Code Meaning Method or cache behavior
300 Multiple Choices More than one representation may satisfy the request. The client may need to choose among alternatives.
301 Moved Permanently The target has a permanent replacement. Clients and search systems may update references. Historical user-agent behavior can change POST to GET, so do not assume method preservation.
302 Found A temporary redirection. Historical user-agent behavior can change POST to GET; use a method-preserving redirect when that distinction matters.
303 See Other Redirects the client to another resource. Commonly used for a subsequent retrieval with GET.
304 Not Modified The cached representation remains valid under the request’s conditional headers. Carries no response content; use the cached representation.
305 Use Proxy Obsolete response code. Do not choose it for new behavior.
307 Temporary Redirect A temporary redirection. Preserves the request method and body.
308 Permanent Redirect A permanent redirection. Preserves the request method and body.

For a temporary redirect that must preserve a POST, 307 is the relevant choice among the listed temporary redirects. For a permanent redirect that must preserve the method and body, use 308. A 301 or 302 may be appropriate when their redirect semantics fit, but clients’ historical method handling makes them a poor assumption for method-sensitive workflows.

4xx client errors

A 4xx code signals that the request, credentials, authorization, or applicable policy prevents fulfillment as sent. When designing an API, choose the most specific accurate code and provide an explanatory response where appropriate. Authentication and authorization are different: 401 concerns missing or invalid authentication and requires a WWW-Authenticate challenge; 403 means the server understood the request but refuses to fulfill it.

Code Meaning and useful clue
400 Bad Request The server cannot or will not process the request because of a perceived client error, such as malformed syntax or invalid framing.
401 Unauthorized Authentication credentials are missing or invalid. The server must send a WWW-Authenticate challenge.
403 Forbidden The server understood the request but refuses to fulfill it; supplying valid authentication does not necessarily change the decision.
404 Not Found No current representation is available, or the server does not wish to disclose that one exists.
405 Method Not Allowed The method is known but unsupported for this target resource. The Allow header should identify supported methods.
406 Not Acceptable No representation matches the request’s proactive content-negotiation criteria.
408 Request Timeout The server did not receive a complete request in time.
409 Conflict The request conflicts with the current state of the target resource.
410 Gone The resource is intentionally and permanently unavailable.
411 Length Required The server requires a request length.
412 Precondition Failed A request precondition was not met.
413 Content Too Large The request content is too large for the server to process.
414 URI Too Long The request URI is too long.
415 Unsupported Media Type The request media type is not supported.
416 Range Not Satisfiable The requested range cannot be supplied.
417 Expectation Failed The server cannot meet the request’s expectations.
418 I’m a teapot An RFC-defined April Fools code, not a general-purpose application error choice.
421 Misdirected Request The request reached a server unable to produce a response for the target authority.
422 Unprocessable Content The content type and syntax are understood, but the instructions are semantically invalid.
423 Locked A specialized registered response.
424 Failed Dependency A specialized registered response.
425 Too Early A specialized registered response.
426 Upgrade Required The client should switch to another protocol.
428 Precondition Required The origin requires a conditional request.
429 Too Many Requests The client sent too many requests in a given period. A Retry-After header may communicate when to back off.
431 Request Header Fields Too Large The request headers are too large.
451 Unavailable For Legal Reasons Access is denied for legal reasons.

5xx server and intermediary errors

These codes generally point investigation toward the origin service, a gateway, a dependency, capacity, or a deployment path. The code alone cannot identify which component failed; trace the request through the architecture and inspect the response source and timing.

Code Meaning Where to look first
500 Internal Server Error A generic unexpected server condition. Application errors and server logs.
501 Not Implemented The server does not support the functionality required to fulfill the request. Whether the server or endpoint implements the requested capability.
502 Bad Gateway A gateway or proxy received an invalid response from an upstream server. The gateway-to-upstream connection and upstream response.
503 Service Unavailable The server is temporarily unable to handle the request, commonly during overload or maintenance. Capacity, maintenance state, and service recovery. A Retry-After header may indicate when to retry.
504 Gateway Timeout A gateway or proxy did not receive a timely response from an upstream server. Upstream latency, timeouts, and the gateway’s request path.
505 HTTP Version Not Supported A specialized registered response. The HTTP version used by the client and supported by the server.
506 Variant Also Negotiates A specialized registered response. Content negotiation configuration.
507 Insufficient Storage A specialized registered response. Storage availability in the relevant system.
508 Loop Detected A specialized registered response. Repeated processing or a loop in the request path.
510 Not Extended A specialized registered response. The extension requirements for the request.
511 Network Authentication Required A specialized registered response. Network-level authentication.

502 versus 504

Both often involve a gateway or proxy, but they describe different failures. A 502 means the gateway received an invalid upstream response. A 504 means it did not receive a timely upstream response. In the first case, inspect what the upstream sent; in the second, investigate whether it responded before the gateway’s timeout.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Unknown, custom, and invalid codes

Clients must understand an unrecognized status by its class and treat it like that class’s x00 code. For example, an unrecognized 471 is handled as a 400-class client error. That rule supports interoperability, but it does not reveal the precise meaning intended by a particular server.

MDN notes that a response absent from its reference may be non-standard or specific to server software. Check the IANA HTTP Status Code Registry and the vendor’s documentation before assigning portable meaning to an unusual code, especially vendor-specific 5xx or 52x responses. Values outside 100–599 are not valid HTTP status codes; a library may still use other numbers internally for failures that are not HTTP responses.

Rank #4
Sale
HTTP: The Definitive Guide
  • Used Book in Good Condition
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Quick troubleshooting by symptom

  • You see 401: Check whether credentials were sent and are valid, then inspect the required authentication scheme in WWW-Authenticate.
  • You see 403: Authentication may have succeeded; check the server’s authorization rules or refusal policy rather than repeatedly resending the same credentials.
  • You see 404: Verify the target path and resource state, while remembering that a server may use 404 to avoid disclosing that a resource exists.
  • A redirect breaks a POST: Check whether the redirect is 301 or 302 and whether the client changed the method. Use 307 or 308 when preserving the method and body is required.
  • You see 405: Check the request method and the response’s Allow header.
  • You see 429 or 503: Check for Retry-After and follow the indicated backoff instead of retrying immediately in a tight loop.
  • You see 502 or 504: Establish whether the gateway received an invalid upstream reply or timed out waiting; then inspect the gateway and upstream logs for the same request.
  • You see an unfamiliar number: Confirm it is within 100–599, interpret its class, then verify the specific registration and server documentation.

Or skip the browser setup

If the task is to capture a page rather than diagnose an HTTP response, ScreenshotNeo is a website screenshot API and MCP server. Its response reports page verdict and billing status in X-Page-Verdict and X-Billed headers; those are product-specific indicators, not substitutes for an HTTP status code. The API supports a one-request screenshot capture; see the ScreenshotNeo API documentation.

For example, this cURL request captures a page as WebP:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo accepts cookie or consent banners as a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each of those steps can be turned off. Bot checks and CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing. Its MCP server provides take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. The Free plan includes 1,000 shots a month with no card; paid plans start at $5 for 3,000 shots.

Sign up for 1,000 free screenshots a month—no card required.

Sources and version context

The normative definitions and behavior described here follow RFC 9110 (IETF, 2022). The IANA HTTP Status Code Registry page states it was last updated 2025-09-15; temporary registrations such as 104 can change or expire. MDN Web Docs maintains a practical status-code reference, crawled 2026-09-27. For implementation decisions, consult the current registry and the documentation for the server or client you are using.

Frequently Asked Questions

Do the last two digits of a status code have a shared meaning?

No. The first digit determines the class; the final two digits do not have a class-categorization role.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can a response phrase such as “Not Found” replace checking the numeric code?

No. Reason phrases are recommendations and may be omitted or changed. Clients should rely on the numeric status semantics and relevant headers.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.