Developer utilities

HTTP Status Codes

Browse every HTTP status code with meanings and common causes.

Runs locally in your browser

72 codes: the RFC standards plus the nginx and Cloudflare extensions that show up in practice, each error class with its common causes.

Informational

The request was received and processing continues.

4 codes
  • 100

    Continue

    The server received the request headers and the client should send the body.

  • 101

    Switching Protocols

    The server accepts the protocol switch requested by the client.

    Common cause Normal for a successful WebSocket handshake.

  • 102

    Processing

    The server received the request and is still working on it.

    Common cause WebDAV extension, used to keep long requests from timing out.

  • 103

    Early Hints

    A preliminary response sent before the final one.

    Common cause Lets the browser preload assets from Link headers during server think time.

Success

The request was received, understood and accepted.

10 codes
  • 200

    OK

    The request succeeded and the response body carries the result.

  • 201

    Created

    A new resource was created, usually with a Location header.

  • 202

    Accepted

    The request was accepted for processing but is not finished yet.

    Common cause Typical reply for an async job that will be polled later.

  • 203

    Non-Authoritative Information

    The payload came from a transforming proxy rather than the origin.

  • 204

    No Content

    The request succeeded and there is deliberately no response body.

    Common cause Common for DELETE and PUT; sending a body here is a protocol error.

  • 205

    Reset Content

    The client should reset the document view, such as clearing a form.

  • 206

    Partial Content

    Only the requested byte range is returned.

    Common cause This is what makes resume and range playback work.

  • 207

    Multi-Status

    The body contains several independent status results.

    Common cause WebDAV extension used by batch operations like PROPFIND.

  • 208

    Already Reported

    Members of a binding were already reported and are not repeated.

    Common cause WebDAV extension that avoids enumerating the same resource twice.

  • 226

    IM Used

    The server fulfilled a request for delta encoding of the resource.

    Common cause Rare; tied to the Delta Encoding extension.

Redirection

The client must take another action to finish the request.

8 codes
  • 300

    Multiple Choices

    Several representations exist and the client should pick one.

  • 301

    Moved Permanently

    The resource now lives at a new URL permanently.

    Common cause Search engines transfer ranking to the target, so use it for real migrations.

  • 302

    Found

    The resource is temporarily at another URL.

    Common cause Historically browsers changed POST into GET here; prefer 307 to keep the method.

  • 303

    See Other

    The result can be fetched from another URL with a GET request.

    Common cause The correct way to redirect after a successful POST.

  • 304

    Not Modified

    The cached copy is still valid and no body is sent.

    Common cause Driven by If-None-Match or If-Modified-Since; not an error.

  • 305

    Use Proxy

    The request must go through the indicated proxy.

    Common cause Deprecated because of security concerns; you should not see it in new code.

  • 307

    Temporary Redirect

    Temporary redirect that preserves the original HTTP method and body.

  • 308

    Permanent Redirect

    Permanent redirect that also preserves the original method and body.

    Common cause Use it instead of 301 when POST requests must stay POST.

Client error

The request itself is wrong: bad syntax, missing credentials or no permission.

31 codes
  • 400

    Bad Request

    The server cannot process the request because of client-side syntax or parameters.

    Common cause Check the request body, query string and Content-Type first.

  • 401

    Unauthorized

    Authentication is required and missing or invalid.

    Common cause The name is misleading: it means unauthenticated, not unauthorised.

  • 402

    Payment Required

    Reserved for paid access; rarely used as originally intended.

    Common cause Some APIs return it when a plan quota has been exhausted.

  • 403

    Forbidden

    The server understood the request but refuses to authorise it.

    Common cause Credentials are valid but lack permission; retrying will not help.

  • 404

    Not Found

    The server found nothing matching the requested URL.

    Common cause Check the path, and whether the route is registered on the server.

  • 405

    Method Not Allowed

    The resource exists but does not support this HTTP method.

    Common cause Read the Allow header to see which methods are accepted.

  • 406

    Not Acceptable

    No representation matches the Accept headers sent by the client.

    Common cause Often caused by an over-strict Accept or Accept-Language header.

  • 407

    Proxy Authentication Required

    The client must authenticate with the proxy first.

    Common cause Seen behind corporate proxies that require credentials.

  • 408

    Request Timeout

    The server timed out waiting for the rest of the request.

    Common cause Usually a slow or dropped client connection, not a server fault.

  • 409

    Conflict

    The request conflicts with the current state of the resource.

    Common cause Classic case: two writers updating the same record concurrently.

  • 410

    Gone

    The resource existed but has been permanently removed.

    Common cause Unlike 404 it tells clients to stop requesting and drop the link.

  • 411

    Length Required

    The request is missing a Content-Length header.

    Common cause POST and PUT must declare how long the body is; chunked encoding avoids the header.

  • 412

    Precondition Failed

    A conditional header such as If-Match evaluated to false.

    Common cause Used for optimistic locking; re-read the resource and retry.

  • 413

    Content Too Large

    The request body exceeds the limit the server accepts.

    Common cause Raise client_max_body_size on nginx or the equivalent limit upstream.

  • 414

    URI Too Long

    The requested URL is longer than the server is willing to parse.

    Common cause Common when a GET query string carries too much data.

  • 415

    Unsupported Media Type

    The payload format is not supported for this method and resource.

    Common cause Check that Content-Type matches what the endpoint parses, e.g. application/json.

  • 416

    Range Not Satisfiable

    The requested byte range cannot be served.

    Common cause Often a stale Range header pointing past the end of the file.

  • 417

    Expectation Failed

    The expectation given in the Expect header cannot be met.

    Common cause Seen when a proxy cannot honour Expect: 100-continue.

  • 418

    I'm a teapot

    Defined as an April Fools joke and kept as an easter egg.

    Common cause Sometimes returned deliberately to block unwanted crawlers.

  • 421

    Misdirected Request

    The connection was reused for a host the server cannot serve.

    Common cause Appears with HTTP/2 connection coalescing and mismatched SNI.

  • 422

    Unprocessable Content

    The syntax is correct but the semantics fail validation.

    Common cause The usual reply for form or schema validation errors.

  • 423

    Locked

    The resource is locked and cannot be modified.

    Common cause WebDAV extension used during collaborative editing.

  • 424

    Failed Dependency

    The request failed because a previous request in the batch failed.

    Common cause WebDAV extension normally paired with 207 Multi-Status.

  • 425

    Too Early

    The server refuses to process a request that might be replayed.

    Common cause Applies to TLS early data (0-RTT) that could not be replayed safely.

  • 426

    Upgrade Required

    The client must switch to a different protocol, usually TLS.

    Common cause Sent by servers that refuse plaintext HTTP.

  • 428

    Precondition Required

    The server requires the request to be conditional.

    Common cause Guards against lost updates from concurrent edits.

  • 429

    Too Many Requests

    The client sent too many requests in a given amount of time.

    Common cause Read Retry-After to know when to try again, and back off.

  • 431

    Request Header Fields Too Large

    The request headers exceed the size the server accepts.

    Common cause Often oversized cookies; raise large_client_header_buffers if legitimate.

  • 451

    Unavailable For Legal Reasons

    The resource is blocked for legal or regulatory reasons.

    Common cause Named after Fahrenheit 451; used for geo or court-ordered blocks.

  • 444

    No Response nginx

    The server closed the connection without sending anything.

    Common cause nginx specific; usually nginx dropping suspicious or abusive clients.

  • 499

    Client Closed Request nginx

    The client disconnected before the server finished responding.

    Common cause nginx logs this when a client gives up; look for slow backend responses.

Server error

The server failed to fulfil a request that looked valid.

19 codes
  • 500

    Internal Server Error

    The server hit an unexpected condition it cannot handle.

    Common cause Look at server logs: this is almost never about the request content.

  • 501

    Not Implemented

    The server does not support the functionality required.

    Common cause Frequently an unimplemented HTTP method on that route.

  • 502

    Bad Gateway

    A gateway or proxy received an invalid response from upstream.

    Common cause The backend process is often down or crashed mid-response.

  • 503

    Service Unavailable

    The server is temporarily unable to handle the request.

    Common cause Overload or maintenance; Retry-After may say when it returns.

  • 504

    Gateway Timeout

    A gateway or proxy did not get a timely upstream response.

    Common cause Raise the proxy read timeout or make the backend faster.

  • 505

    HTTP Version Not Supported

    The server does not support the HTTP version used in the request.

    Common cause Rare today; mostly an HTTP/1.1-only server receiving a newer protocol.

  • 506

    Variant Also Negotiates

    Content negotiation is misconfigured and loops.

    Common cause A server configuration bug, not a client problem.

  • 507

    Insufficient Storage

    The server cannot store the representation needed to complete the request.

    Common cause WebDAV extension; check disk and quota on the server.

  • 508

    Loop Detected

    The server detected an infinite loop while processing the request.

    Common cause WebDAV extension, typically a cyclic collection hierarchy.

  • 510

    Not Extended

    Further extensions to the request are required to fulfil it.

    Common cause Part of the HTTP Extension Framework, which never saw wide adoption.

  • 511

    Network Authentication Required

    The client needs to authenticate to gain network access.

    Common cause This is the captive portal page on hotel and airport Wi-Fi.

  • 520

    Web Server Returned an Unknown Error Cloudflare

    Cloudflare received an empty or unknown response from the origin.

    Common cause Check origin logs and whether the process crashed mid-request.

  • 521

    Web Server Is Down Cloudflare

    Cloudflare could not connect because the origin refused it.

    Common cause The web server is stopped, or a firewall blocks Cloudflare IPs.

  • 522

    Connection Timed Out Cloudflare

    The TCP handshake with the origin timed out.

    Common cause Origin firewall is silently dropping packets from Cloudflare.

  • 523

    Origin Is Unreachable Cloudflare

    Cloudflare could not reach the origin at all.

    Common cause Usually a wrong origin IP or a broken DNS record.

  • 524

    A Timeout Occurred Cloudflare

    The origin accepted the connection but took too long to respond.

    Common cause Origin exceeded Cloudflare 100 second limit; fix the slow endpoint.

  • 525

    SSL Handshake Failed Cloudflare

    The TLS handshake between Cloudflare and the origin failed.

    Common cause Check the origin certificate, cipher suites and TLS version.

  • 526

    Invalid SSL Certificate Cloudflare

    The origin certificate could not be validated.

    Common cause Expired, self-signed or hostname-mismatched certificate.

  • 527

    Railgun Listener to Origin Error Cloudflare

    The connection between Railgun and the origin failed.

    Common cause Legacy Cloudflare Railgun feature; retry or disable Railgun.