Skip to content
TabBench

HTTP status codes explained: what 200, 301, 404 and 500 mean

By TabBenchHow we check our guides

Every HTTP response begins with a three-digit status code. It is the server's one-word answer to your request: it worked, it moved, you did something wrong, or we did. Once you know the five classes, most codes can be read at a glance, and the few that cause confusion (401 against 403, 301 against 302, 502 against 504) are easy to tell apart.

This guide walks through the classes, the codes you will actually meet, what usually causes each error, and how to choose the right code when you build your own API. Use the lookup tool for any code not covered here, including the non-standard ones you find in nginx and Cloudflare logs.

Open the HTTP Status Code LookupFree, no sign-up, and your file never leaves your browser.

Step by step

  1. Learn the five classes

    The first digit tells you the family. 1xx is informational (the request is still being processed), 2xx means success, 3xx means you need to go somewhere else, 4xx means the request was wrong, and 5xx means the server failed. A client error (4xx) needs a change to the request before it can succeed; a server error (5xx) might succeed if you simply try again later.

  2. Recognise the success codes

    200 OK is the default success. 201 Created follows a successful creation and should carry a Location header with the new resource's URL. 202 Accepted means the work was queued and is not finished. 204 No Content means success with nothing to return, common after DELETE. 206 Partial Content answers a Range request, which is how video seeking and resumable downloads work.

  3. Handle redirects correctly

    301 Moved Permanently and 308 Permanent Redirect say a resource has a new address for good; search engines transfer ranking signals and browsers cache the redirect. 302 Found and 307 Temporary Redirect mean the move is temporary. The difference within each pair is the method: 307 and 308 keep it (a POST stays a POST), while 301 and 302 may turn a POST into a GET. 303 See Other sends the browser to a result page after a form submit. 304 Not Modified is not a redirect at all: it tells the browser its cached copy is still good.

  4. Diagnose client errors (4xx)

    400 Bad Request means the request is malformed: invalid JSON, a missing field or a corrupt cookie. 401 Unauthorized really means unauthenticated: send valid credentials. 403 Forbidden means the server knows who you are and refuses anyway: check permissions, IP rules and any firewall. 404 Not Found means there is nothing at that URL; 410 Gone says it was removed on purpose. 405 Method Not Allowed lists the allowed methods in an Allow header. 409 Conflict and 422 Unprocessable Content report a clash with the current state or a validation failure. 429 Too Many Requests means you hit a rate limit: wait for Retry-After.

  5. Diagnose server errors (5xx)

    500 Internal Server Error is the catch-all for an unhandled failure; read the application's error log. 502 Bad Gateway, 503 Service Unavailable and 504 Gateway Timeout usually come from a proxy, load balancer or CDN in front of your application: 502 means it got an invalid answer, 503 means the service is overloaded or down for maintenance, and 504 means the application took too long. Check whether the application is running and reachable from the proxy before touching proxy settings.

  6. Return the right code from your own API

    Use the most specific code that is true. 201 after creating, 204 after deleting, 400 for malformed input, 401 when credentials are missing, 403 when they are not enough, 404 for unknown resources, 409 for conflicts, 422 for validation errors and 429 when rate limiting. Always include a helpful body with the reason. Avoid returning 200 with an error message inside: generic clients, caches and monitoring tools rely on the code.

Things worth knowing

  • A 5xx error may succeed on retry, but only retry idempotent requests automatically: GET, PUT, DELETE and HEAD are safe, POST usually is not.
  • Honour the Retry-After header on 429 and 503 responses instead of retrying immediately.
  • Status codes from proxies such as nginx and Cloudflare (499, 520 to 530) are not part of the HTTP standard but are common in logs.
  • A soft 404, a page that says “not found” but returns 200, confuses search engines. Return a real 404.

Frequently asked questions

What is the difference between 401 and 403?

401 means the server does not know who you are: credentials are missing or invalid. 403 means it knows who you are, or does not care, and refuses the request anyway. Logging in fixes a 401; it does not fix a 403.

Should I use a 301 or a 302 redirect for SEO?

Use 301 (or 308) for permanent moves, such as a changed URL or http to https, so ranking signals transfer to the new address. Use 302 (or 307) only when the move is temporary and you want the original URL to stay indexed.

What does a 502 Bad Gateway mean?

A proxy or gateway got an invalid or no response from the server behind it. The cause is almost always the upstream application: it crashed, is restarting, listens on a different port, or returned something malformed.

Is 418 I'm a teapot a real status code?

It comes from an April Fools' RFC about coffee-pot control. It is reserved in the registry and a few servers return it as a joke or to reject bots, but it is not meant for real use.