The server cannot process the request because its syntax, framing, or supplied data is invalid. Repeating the same request unchanged is unlikely to help.
Operational guidance: Inspect URL encoding, JSON/body syntax, required fields, and request framing.
The request lacks valid authentication credentials for the target. Despite its name, this response means authentication is required or failed.
Operational guidance: Send the expected credentials and include a WWW-Authenticate challenge.
Reserved for future use, though some products use it for payment or quota workflows. There is no single universally interoperable payment behavior.
Operational guidance: Treat vendor-specific meanings as such; document the API contract.
The server understood the request but refuses to fulfill it. Valid credentials do not necessarily change the outcome because the restriction may be policy-based.
Operational guidance: Check permissions, access policy, IP/WAF rules, and resource-level authorization.
The server cannot find a current representation for the requested URI, or is unwilling to disclose that one exists. The response alone does not say whether absence is temporary or permanent.
Operational guidance: Repair the URL, restore the resource, or use 410 when removal is known to be permanent.
The resource exists, but it does not support the method used in this request.
Operational guidance: Return an Allow header listing methods the resource accepts.
The server cannot produce a representation matching the client’s proactive Accept preferences.
Operational guidance: Relax Accept constraints or configure a suitable representation/negotiation policy.
407Proxy Authentication Required
An intermediary proxy requires credentials before it will forward the request.
Operational guidance: Authenticate to the proxy using Proxy-Authenticate / Proxy-Authorization; this is distinct from origin authentication.
The server did not receive the complete request in the time it was prepared to wait. The client may retry on a new connection.
Operational guidance: Check network stalls, upload size, and server/proxy timeout settings.
The request conflicts with the current state of the resource, such as a version collision or an attempt to create a duplicate.
Operational guidance: Explain the conflict and provide enough current state for the client to resolve it.
The resource is intentionally and likely permanently unavailable, with no known replacement. This is stronger than a generic not-found response.
Operational guidance: Use when removal is deliberate; remove obsolete internal links and references.
The server requires a Content-Length header but the request did not provide one.
Operational guidance: Send an accurate Content-Length or use a supported transfer framing.
A request condition such as If-Match evaluated to false, so the server did not perform the requested action.
Operational guidance: Refresh the representation and retry with current validators/state.
The request body exceeds a limit the server is willing or able to process. The server may close the connection or allow retry after reducing the body.
Operational guidance: Reduce payload size or adjust documented upload limits.
The request target is longer than the server is willing to interpret, often due to an oversized query string.
Operational guidance: Use a shorter URI or move suitable data into a request body.
415Unsupported Media Type
The server refuses the request body because its media type, content encoding, or inspected format is unsupported.
Operational guidance: Send a supported Content-Type/encoding and a body matching it.
The requested byte range cannot be served, for example because it starts beyond the representation length.
Operational guidance: Re-check resource length and range units; servers may return Content-Range: bytes */length.
The server or intermediary cannot meet an expectation declared in the Expect header.
Operational guidance: Retry without the unsupported expectation when safe and appropriate.
A humorous status originating in an April Fools’ specification. It is not a normal application error contract, although some services use it playfully.
Operational guidance: Do not depend on it for interoperable production behavior.
The request reached a server that cannot produce an authoritative response for the target URI, often because connection routing or HTTP authority does not match.
Operational guidance: Retry over a suitable connection and inspect Host/:authority, SNI, and proxy routing.
The content type and syntax are understood, but the server cannot apply the instructions or validate the submitted content.
Operational guidance: Return actionable field-level validation details; correcting the payload may allow success.
A WebDAV resource is locked, so the requested method cannot be performed until the lock condition is resolved.
Operational guidance: Check lock ownership, timeout, and WebDAV lock-token handling.
A WebDAV operation failed because a required preceding operation in the same request sequence failed.
Operational guidance: Resolve the earlier failed action before retrying dependent operations.
The server declines to process a request that may have been replayed during early data, to reduce replay risk.
Operational guidance: Retry after the connection is established without early data.
The server refuses the current protocol and indicates that the client should switch to another one.
Operational guidance: Include an Upgrade header that describes supported protocol choices.
The server requires a conditional request to prevent lost updates, but the client sent an unconditional one.
Operational guidance: Fetch current state and submit an appropriate condition such as If-Match.
The client has sent too many requests in a given period, based on a server-defined rate limit.
Operational guidance: Back off, honor Retry-After when present, and avoid synchronized retry bursts.
431Request Header Fields Too Large
The server will not process the request because one or more header fields, or the combined header set, is too large.
Operational guidance: Reduce cookies/custom headers or adjust an intentional server limit.
451Unavailable For Legal Reasons
The server cannot provide the requested resource because of a legal restriction.
Operational guidance: Where appropriate, explain the restriction and its scope without exposing protected information.