HTTP Status Code Lookup
Look up the meaning of an HTTP status code.
- 100Continue
The client should continue sending the request body. Sent in response to an Expect: 100-continue header.
RFC 9110 - 101Switching Protocols
The server is switching protocols as requested by the client's Upgrade header — a WebSocket handshake, for example.
RFC 9110 - 102Processing
The server accepted the request but hasn't finished it. Used by WebDAV to keep long operations from timing out.
RFC 2518 - 103Early Hints
Preliminary response carrying Link headers so the client can preload resources while the final response is prepared.
RFC 8297 - 200OK
The request succeeded. The meaning of the body depends on the method — GET returns the resource, POST returns the result of the action.
RFC 9110 - 201Created
The request succeeded and created a new resource. The Location header should point to it.
RFC 9110 - 202Accepted
The request was accepted for processing but hasn't completed. Typical for queued or asynchronous work.
RFC 9110 - 203Non-Authoritative Information
The response is a modified version of the origin's payload, usually rewritten by a proxy.
RFC 9110 - 204No Content
The request succeeded and there is no body to return. Common for DELETE and for PUT updates.
RFC 9110 - 205Reset Content
The request succeeded; the client should reset the document view — clear the form that sent the request.
RFC 9110 - 206Partial Content
The server is delivering part of the resource in response to a Range header. Used for resumable downloads and media seeking.
RFC 9110 - 207Multi-Status
The body is an XML document with separate status codes for multiple independent operations (WebDAV).
RFC 4918 - 208Already Reported
Members of a WebDAV binding were already enumerated in a previous part of the multi-status response.
RFC 5842 - 226IM Used
The server fulfilled a GET and the response is the result of instance manipulations applied to the current instance.
RFC 3229 - 300Multiple Choices
The request has more than one possible response; the client or user should pick one.
RFC 9110 - 301Moved Permanently
The resource has a new permanent URL in the Location header. Clients and search engines should update their links.
RFC 9110 - 302Found
The resource is temporarily at a different URL. Clients historically switch POST to GET — use 307 to avoid that.
RFC 9110 - 303See Other
Fetch the resource at the Location URL with GET. The usual redirect after a successful POST.
RFC 9110 - 304Not Modified
The cached copy is still fresh, so no body is sent. Returned for conditional requests using If-None-Match or If-Modified-Since.
RFC 9110 - 305Use Proxy
The resource must be accessed through a proxy. Deprecated for security reasons and no longer honoured by browsers.
RFC 9110Deprecated - 307Temporary Redirect
Same as 302, but the method and body must not be changed when the request is repeated at the new URL.
RFC 9110 - 308Permanent Redirect
Same as 301, but the method and body must not be changed when the request is repeated at the new URL.
RFC 9110 - 400Bad Request
The server can't parse the request — malformed syntax, invalid framing, or deceptive routing.
RFC 9110 - 401Unauthorized
Authentication is required or failed. Despite the name it means unauthenticated; the response carries a WWW-Authenticate header.
RFC 9110 - 402Payment Required
Reserved for future use. Some APIs return it when a plan limit is hit or a subscription lapsed.
RFC 9110 - 403Forbidden
The server understood the request but refuses it. Re-authenticating won't help — unlike 401.
RFC 9110 - 404Not Found
The server has no resource at this URL and won't say whether it ever did.
RFC 9110 - 405Method Not Allowed
The resource exists but doesn't support this method. The response must list supported methods in Allow.
RFC 9110 - 406Not Acceptable
No representation matches the request's Accept, Accept-Language, or Accept-Encoding headers.
RFC 9110 - 407Proxy Authentication Required
Like 401, but the client must authenticate with the proxy identified in Proxy-Authenticate.
RFC 9110 - 408Request Timeout
The server closed an idle connection because the client took too long to send the request.
RFC 9110 - 409Conflict
The request conflicts with the current state of the resource — a concurrent edit or a duplicate unique value.
RFC 9110 - 410Gone
The resource was deliberately removed and won't come back. A permanent, intentional 404.
RFC 9110 - 411Length Required
The server refuses the request because it has no Content-Length header.
RFC 9110 - 412Precondition Failed
A conditional header such as If-Match or If-Unmodified-Since evaluated to false. The usual optimistic-locking failure.
RFC 9110 - 413Content Too Large
The request body exceeds the server's limit. Previously called Payload Too Large.
RFC 9110 - 414URI Too Long
The request target is longer than the server will interpret — often a GET that should have been a POST.
RFC 9110 - 415Unsupported Media Type
The body's Content-Type isn't supported by the target resource.
RFC 9110 - 416Range Not Satisfiable
The requested Range lies outside the size of the resource.
RFC 9110 - 417Expectation Failed
The expectation in the Expect header can't be met by the server.
RFC 9110 - 418I'm a teapot
An April Fools' joke from the Hyper Text Coffee Pot Control Protocol. Some servers return it for automated or unwanted traffic.
RFC 2324 - 419Page Expired
Laravel returns this when a CSRF token has expired and the form must be resubmitted.
LaravelNon-standard - 420Enhance Your Calm
Rate limiting on the retired Twitter API v1. Modern APIs use 429 instead.
TwitterNon-standard - 421Misdirected Request
The request reached a server that can't produce a response for this authority — a connection-reuse mismatch under HTTP/2.
RFC 9110 - 422Unprocessable Content
The syntax is valid but the content is semantically wrong. The standard validation-failure code for JSON APIs.
RFC 9110 - 423Locked
The resource is locked (WebDAV).
RFC 4918 - 424Failed Dependency
The request failed because a request it depended on failed (WebDAV).
RFC 4918 - 425Too Early
The server won't process a request sent in TLS early data, to avoid replay attacks.
RFC 8470 - 426Upgrade Required
The client must switch to a different protocol, listed in the Upgrade header.
RFC 9110 - 428Precondition Required
The server requires a conditional request so concurrent updates can't silently overwrite each other.
RFC 6585 - 429Too Many Requests
The client is rate limited. A Retry-After header says when to try again.
RFC 6585 - 431Request Header Fields Too Large
The headers are too large in total, or one header is — often an oversized cookie.
RFC 6585 - 440Login Time-out
The session expired and the client must log in again (IIS).
Microsoft IISNon-standard - 444No Response
nginx closes the connection without sending a response, typically to drop malicious requests.
nginxNon-standard - 451Unavailable For Legal Reasons
Access is denied for legal reasons such as a takedown order or geo-blocking. The number nods to Fahrenheit 451.
RFC 7725 - 494Request Header Too Large
nginx's predecessor to 431 for oversized headers.
nginxNon-standard - 499Client Closed Request
The client disconnected before nginx could respond. Usually a cancelled request or a client-side timeout.
nginxNon-standard - 500Internal Server Error
An unhandled error on the server. The generic catch-all when nothing more specific applies.
RFC 9110 - 501Not Implemented
The server doesn't support the functionality needed — an unrecognised method, for example.
RFC 9110 - 502Bad Gateway
A gateway or proxy got an invalid response from the upstream server it was talking to.
RFC 9110 - 503Service Unavailable
The server is overloaded or down for maintenance. Should be temporary and may include Retry-After.
RFC 9110 - 504Gateway Timeout
A gateway or proxy didn't get a response from the upstream server in time.
RFC 9110 - 505HTTP Version Not Supported
The HTTP version used in the request isn't supported by the server.
RFC 9110 - 506Variant Also Negotiates
Content negotiation is misconfigured: the chosen variant is itself a negotiating resource.
RFC 2295 - 507Insufficient Storage
The server can't store the representation needed to complete the request (WebDAV).
RFC 4918 - 508Loop Detected
The server aborted the operation because it found an infinite loop while processing it (WebDAV).
RFC 5842 - 510Not Extended
Further extensions to the request are required for the server to fulfil it.
RFC 2774 - 511Network Authentication Required
The client must authenticate to get network access — the code behind captive-portal WiFi logins.
RFC 6585 - 520Web Server Returned an Unknown Error
Cloudflare got an empty, unknown, or malformed response from the origin server.
CloudflareNon-standard - 521Web Server Is Down
Cloudflare could not reach the origin server — the connection was refused.
CloudflareNon-standard - 522Connection Timed Out
Cloudflare timed out while opening a TCP connection to the origin server.
CloudflareNon-standard - 523Origin Is Unreachable
Cloudflare cannot reach the origin — often a DNS or routing problem.
CloudflareNon-standard - 524A Timeout Occurred
Cloudflare connected to the origin but didn't get an HTTP response before the timeout.
CloudflareNon-standard - 525SSL Handshake Failed
The TLS handshake between Cloudflare and the origin server failed.
CloudflareNon-standard - 526Invalid SSL Certificate
Cloudflare could not validate the origin server's TLS certificate.
CloudflareNon-standard - 530Site Frozen / Origin Error
Cloudflare returns 530 alongside a 1xxx error code that carries the real cause.
CloudflareNon-standard - 599Network Connect Timeout Error
Used by some proxies to signal that a network connection timed out behind the proxy.
Proxy conventionNon-standard