HTTP status codes
Look up any HTTP status code by number or by word, with plain-English meaning, common causes, fixes and the RFC that defines it.
Runs entirely in your browser
Lists the codes in the IANA HTTP Status Code Registry, with 306 and 418 shown as the reserved codes they are, plus a short set of widely seen unofficial codes from nginx, Cloudflare and Laravel, labelled with their source. Other vendor-specific codes are not covered.
How to look up a status code
- Type the number, such as
502, or a word, such as rate limit or redirect, into the search box. - Narrow the list with the class buttons: 1xx to 5xx for the standard codes, or Unofficial for nginx, Cloudflare and Laravel codes.
- Open a code to see when it appears and what to do about it as a client and as the owner of the server. Use the # link to share a direct link to that code.
Reading HTTP status codes
Every HTTP response begins with a three-digit status code that tells the client what happened to its request. The first digit gives the family: 1xx for progress messages, 2xx for success, 3xx for redirection, 4xx for a problem with the request and 5xx for a failure on the server. A program that does not know a particular code can still act correctly by looking at that first digit, which is why new codes can be added without breaking old clients.
The official list is kept in the IANA HTTP Status Code Registry, and the meanings are written in RFC 9110 (HTTP Semantics) and a handful of other RFCs for WebDAV and extensions. The reason phrase after the number, such as Not Found, is only a label; HTTP/2 and HTTP/3 do not carry it. A few phrases were renamed in 2022, so 413 is now Content Too Large and 422 is Unprocessable Content.
Servers outside the standards also invent codes. nginx logs 499 when a client hangs up, and Cloudflare uses 520 to 526 to describe failures between its network and your origin. They appear here in a separate group so they are not mistaken for registered codes. When debugging, remember that the code you see may come from a proxy or CDN in front of your application, not from the application itself.
Tips
- Got a failing request with special characters in its address? Encode or decode it with URL encode and decode.
- Read the response body of an API error with the JSON formatter.
- A 403 for a particular browser or bot? Check what the client sends with the user agent parser.
Questions
What do the five classes of status code mean?
The first digit sets the class. 1xx is informational and the request is still going, 2xx means success, 3xx means the client must take another step (usually a redirect), 4xx means the request has a problem on the client's side, and 5xx means the server failed on a request that looked valid.
What is the difference between 401 and 403?
401 means the server does not know who you are: credentials are missing, wrong or expired, and logging in may fix it. 403 means it knows who you are and you are not allowed to do this, so sending the same credentials again will not help.
Should I use 301 or 302 for a redirect?
Use 301 (or 308) when the move is permanent, so that browsers and search engines switch to the new address. Use 302 (or 307) when the old address will come back. 307 and 308 keep the request method, while 301 and 302 let older clients turn a POST into a GET.
Is 418 I'm a teapot a real status code?
It began as an April Fools' joke in RFC 2324 for a coffee-pot control protocol. IANA now lists 418 as unused, reserved so that it is not given a real meaning. Some sites still return it for fun or to turn away scrapers, but it is not a standard response.
What are 520 to 526 and 499?
They are not in the HTTP standards. 520 to 526 are Cloudflare errors that report problems between Cloudflare and your own server, and 499 is an nginx log code for a client that disconnected before the reply. They are shown in the Unofficial group with their source.
Why does a 5xx error sometimes disappear when I retry?
Many 5xx errors come from overload, a restarting backend or a short network fault, which can clear within seconds. Retrying with a growing delay is safe for idempotent requests such as GET; for POST, check that the first attempt did not already succeed.