Every HTTP status code you'll meet β standard, de facto, and common non-standard β with what it means, when to send it, and the 2026 adoption notes. Jump by class or Ctrl+F for a specific number.
Updated October 2026 Β· based on RFC 9110 (2022) + ongoing IANA registry.
The server is telling the client "I've seen your request, keep going". Final response will come separately. 103 is the big modern one β used by Cloudflare and Fastly for preloading since 2023, now common in production.
| Code | Name | When to use |
|---|---|---|
| 100 | Continue | Client sent Expect: 100-continue and should keep sending the body. |
| 101 | Switching Protocols | Response to Upgrade:, used by WebSockets. |
| 102 | Processing (WebDAV) | Request is being processed, no response yet. Rarely seen outside WebDAV. |
| 103 | Early Hints | Preload hints before the real response. Big LCP win if your CDN supports it (Cloudflare, Fastly, Chrome 103+). |
| Code | Name | When to use |
|---|---|---|
| 200 | OK | Default success. GET returns the resource; POST returns the result. |
| 201 | Created | POST/PUT created a new resource. Include Location: header. |
| 202 | Accepted | Request accepted but not processed yet (async job). |
| 203 | Non-Authoritative Information | Returned content was modified by a proxy. Rare in practice. |
| 204 | No Content | Success with no body β common for PUT/DELETE, or empty API responses. |
| 205 | Reset Content | Tells the client to reset the form that triggered the request. Barely used. |
| 206 | Partial Content | Response to a Range: request (video streaming, resumable downloads). |
| 207 | Multi-Status (WebDAV) | XML body with per-resource statuses. |
| 208 | Already Reported (WebDAV) | Member of a bound collection, already enumerated. |
| 226 | IM Used | Delta encoding; essentially a museum piece. |
| Code | Name | When to use |
|---|---|---|
| 300 | Multiple Choices | Server offers several representations; client picks. Essentially unused. |
| 301 | Moved Permanently | Permanent redirect. Cached hard β hard to undo. Use for domain/URL rename. |
| 302 | Found | Temporary redirect. Historically ambiguous on method change; most clients convert POSTβGET. |
| 303 | See Other | After a POST, redirect to a GET. The modern "POST-redirect-GET" pattern. |
| 304 | Not Modified | Conditional GET matched If-Modified-Since or If-None-Match. No body. |
| 305 | Use Proxy | Deprecated β browsers refuse it for security. |
| 307 | Temporary Redirect | Like 302 but method is preserved. POST stays POST. |
| 308 | Permanent Redirect | Like 301 but method is preserved. Modern replacement for 301. |
| Code | Name | When to use |
|---|---|---|
| 400 | Bad Request | Malformed request β bad JSON, bad params. Default for client-side errors you can't categorize. |
| 401 | Unauthorized | Credentials required and missing/invalid. Must include WWW-Authenticate header. (Actually means "unauthenticated".) |
| 402 | Payment Required | Reserved. Stripe/Lemon Squeezy sometimes use it for "upgrade your plan". |
| 403 | Forbidden | Authenticated but not allowed. Correct code for "logged in but can't access this". |
| 404 | Not Found | Resource doesn't exist. Can also mean "exists but you can't know" (avoids leaking info). |
| 405 | Method Not Allowed | GET on a POST-only endpoint, etc. Must include Allow: header listing valid methods. |
| 406 | Not Acceptable | Server can't match Accept: header. Rare. |
| 407 | Proxy Authentication Required | Like 401 but for a proxy. |
| 408 | Request Timeout | Client took too long sending the request. |
| 409 | Conflict | Request conflicts with current state β edit conflict, duplicate key. |
| 410 | Gone | Resource used to exist, now permanently removed. Strongly cached. Signals to Google to deindex faster than 404. |
| 411 | Length Required | Request lacks Content-Length. |
| 412 | Precondition Failed | A conditional header (If-Match, etc) didn't match. Use for optimistic concurrency. |
| 413 | Content Too Large | Request body exceeds server limit. (Was "Payload Too Large".) |
| 414 | URI Too Long | Usually seen with runaway GET-with-many-params. |
| 415 | Unsupported Media Type | Server doesn't accept the Content-Type. |
| 416 | Range Not Satisfiable | Client asked for a byte range outside the resource. |
| 417 | Expectation Failed | Server can't satisfy the Expect: header. |
| 418 | I'm a teapot | Joke RFC. Returned by actual teapots and some error pages. Not for serious use. |
| 421 | Misdirected Request | Request was routed to a server that can't produce a response. HTTP/2 connection reuse edge case. |
| 422 | Unprocessable Content | Request is well-formed but semantically invalid. Classic for validation failures. |
| 423 | Locked (WebDAV) | Resource is locked. |
| 424 | Failed Dependency (WebDAV) | Previous request in a sequence failed. |
| 425 | Too Early | Server unwilling to risk processing an early-data request (TLS 1.3 0-RTT). |
| 426 | Upgrade Required | Client should switch protocols (e.g., to TLS). Include Upgrade: header. |
| 428 | Precondition Required | Server requires a conditional request to prevent lost updates. |
| 429 | Too Many Requests | Rate limiting. Include Retry-After:. |
| 431 | Request Header Fields Too Large | Headers (cumulative or single) exceed server limit. |
| 451 | Unavailable For Legal Reasons | GDPR removal, DMCA takedown, government censorship. The "451" is a nod to Fahrenheit 451. |
| Code | Name | When to use |
|---|---|---|
| 500 | Internal Server Error | Catch-all for unhandled server exceptions. Should be rare and alertable. |
| 501 | Not Implemented | Method or feature isn't supported. Different from 405: 405 = known endpoint, wrong method; 501 = method unknown to server. |
| 502 | Bad Gateway | Upstream (origin, app server) returned garbage or died. |
| 503 | Service Unavailable | Temporarily down β maintenance, overloaded. Include Retry-After:. |
| 504 | Gateway Timeout | Upstream didn't respond in time. |
| 505 | HTTP Version Not Supported | Client used an HTTP version the server refuses. |
| 506 | Variant Also Negotiates | Content negotiation misconfiguration. Rare. |
| 507 | Insufficient Storage (WebDAV) | Can't store the submitted representation. |
| 508 | Loop Detected (WebDAV) | Infinite loop processing the request. |
| 510 | Not Extended | Server needs an HTTP extension the client didn't declare. Essentially unused. |
| 511 | Network Authentication Required | Captive portals ("sign in to Wi-Fi"). Should include a login URL. |
| Code | Source | Means |
|---|---|---|
| 444 | nginx | Connection closed without a response. Used to drop bad clients. |
| 494 | nginx | Request header too large. |
| 495 | nginx | SSL certificate error. |
| 496 | nginx | SSL certificate required but not provided. |
| 497 | nginx | HTTP sent to HTTPS port. |
| 499 | nginx | Client closed the connection before the server responded. |
| 520 | Cloudflare | Unknown error from the origin. |
| 521 | Cloudflare | Origin web server refused the connection. |
| 522 | Cloudflare | Connection to origin timed out. |
| 523 | Cloudflare | Origin unreachable (routing issue). |
| 524 | Cloudflare | A timeout occurred reading from origin. |
| 525 | Cloudflare | SSL handshake with origin failed. |
| 526 | Cloudflare | Origin SSL certificate invalid. |
| 530 | Cloudflare | Error on Cloudflare's side. Often paired with another 5xx in the body. |
401, not 403. 401 means "no credentials or bad credentials β try again". Must include WWW-Authenticate header.
403, not 401. Resending the same credentials won't help.
If leaking "exists" is sensitive (private repo, invite-only post), return 404 for both. Otherwise 404 vs 403 is a UX choice.
422 is the precise code. 400 is widely accepted but less specific. Pick one convention per API and stick to it.
429 with Retry-After: <seconds>. Include a JSON body explaining which limit was hit if you can.
451 is the correct code. Google will treat it differently from 404 for crawl purposes.
503 with Retry-After:. Google won't deindex a page returning 503 for a short time, but it will if you leave it there for days.
308 if permanent (preserves POST/PUT bodies). 307 if temporary. Use 301/302 only if you need to interoperate with ancient clients.
303 See Other. Classic "Post-Redirect-Get" pattern β prevents accidental re-submits on refresh.