Skip to main content

HTTP Status Code Reference

Search 31 common status codes. 401 vs 403 and 502 vs 503 included.

CodeName
100Continue
101Switching Protocols
102Processing
200OK
201Created
202Accepted
204No Content
206Partial Content
301Moved Permanently
302Found
303See Other
304Not Modified
307Temporary Redirect
308Permanent Redirect
400Bad Request
401Unauthorized
403Forbidden
404Not Found
405Method Not Allowed
408Request Timeout
409Conflict
410Gone
412Precondition Failed
415Unsupported Media Type
422Unprocessable Entity
429Too Many Requests
500Internal Server Error
501Not Implemented
502Bad Gateway
503Service Unavailable
504Gateway Timeout

Easy to mix up

401 vs 403: 401 means not authenticated (missing or bad credentials). 403 means authenticated but not allowed.

502 vs 503: 502 means a proxy got a bad response from upstream. 503 means the origin itself is unavailable or overloaded.

HTTP Status Code Reference

HTTP status codes tell a client whether a request succeeded, redirected, or failed. This reference lists the common codes with a short explanation of when to use them and how clients typically handle them.

Search by number or phrase. The long-tail questions — 401 vs 403, 502 vs 503 — are called out because they are easy to mix up when you are writing APIs or reading production logs. Pair with the header analyzer when you are debugging a full response.

Tips

  • 401 Unauthorized means the client has not authenticated (or the credentials failed). 403 Forbidden means the client is authenticated but not allowed.
  • 502 Bad Gateway means a proxy got an invalid response from upstream. 503 Service Unavailable means the origin is overloaded or down for maintenance.
  • Prefer 404 over 403 for resources you do not want to confirm exist.

More from Shane Code