HTTP Status Codes Explained (1xx–5xx)
Every HTTP response comes with a status code. Knowing the classes — and a handful of common codes — tells you almost immediately whether a request succeeded, was redirected, or failed, and whose fault it was.
The five classes
The first digit tells you the category:
- 1xx Informational — the request was received and processing continues.
- 2xx Success — the request succeeded (
200 OK,201 Created). - 3xx Redirection — further action is needed, usually following a new URL.
- 4xx Client Error — the request was wrong (bad syntax, missing auth, unknown URL). Your side to fix.
- 5xx Server Error — the server failed to fulfill a valid request. Their side to fix.
That 4xx-vs-5xx split is the single most useful thing to internalize: 4xx means fix the request, 5xx means the server broke.
Codes you'll actually see
- 200 OK — success.
- 201 Created — a POST/PUT created a resource.
- 204 No Content — success with nothing to return.
- 301 / 302 — permanent / temporary redirect.
- 304 Not Modified — your cached copy is still current.
- 400 Bad Request — malformed request.
- 401 Unauthorized — you're not authenticated.
- 403 Forbidden — authenticated, but not allowed.
- 404 Not Found — no such resource.
- 429 Too Many Requests — you're being rate-limited.
- 500 Internal Server Error — the generic server failure.
- 502 / 503 / 504 — bad gateway / unavailable / gateway timeout, common behind proxies and load balancers.
401 vs 403
A frequent mix-up: 401 Unauthorized actually means unauthenticated — the server doesn't know who you are. 403 Forbidden means it knows who you are and you're still not allowed. Different fixes: authenticate vs get permission.
Related
Part of The Complete Guide to HTTP. Debugging a request? Parse its HTTP headers or tidy up the curl command you're testing with.
Try it
Type a code like 404, a class like 5, or a keyword like redirect to look up any status code — instantly, in your browser.