Technical reference

HTTP Response Status Codes

HTTP status codes are three-digit signals in a server response. Their first digit identifies the broad outcome; the remaining digits identify a particular condition. This guide explains registered standard codes with practical context, plus notable provider-specific values that may appear in logs.

How to read this catalogue: A status is not a complete diagnosis by itself. Check the request method, response headers, body, redirect target, and the server or proxy that generated it. Unrecognized values generally retain the meaning of their first-digit class, but their exact behavior may be implementation-specific.

Browser compatibility and response handling

HTTP status codes are part of the HTTP protocol, not a browser feature that each vendor implements as a separate web API. Current browsers can handle the standard response classes; visible error pages and retry behavior are browser-specific. Support for newer interim responses and specialized extensions can differ by version and network path.

Response familyChrome / EdgeFirefoxSafariOperaAndroid / iOS WebViewCompatibility note
1xx informationalSupported as protocol interim responsesSupported as protocol interim responsesSupported as protocol interim responsesSupported as protocol interim responsesSupported by the underlying network stack100/101 are established; 102 is niche/deprecated. 103 Early Hints adoption and observable preload behavior vary by browser version, server, and intermediary.
2xx successSupportedSupportedSupportedSupportedSupportedStandard success semantics are shared. Body rules still matter: for example, 204 and 205 have no response body.
3xx redirectionSupportedSupportedSupportedSupportedSupportedLocation, method, cache, and security policy affect navigation. 301/302 may change POST to GET; 307/308 preserve the method.
4xx client/request errorSupportedSupportedSupportedSupportedSupportedThe browser receives the response; whether it displays the server body or a browser-generated error view differs by status and product.
5xx server errorSupportedSupportedSupportedSupportedSupportedClients can process the response class, but proxy-generated pages, retry behavior, and diagnostic UI are not identical across browsers.
Unknown code in a known classClass-level handlingClass-level handlingClass-level handlingClass-level handlingClass-level handlingHTTP clients can infer the general class from the first digit; do not rely on a custom code having standard semantics or identical UI.

Compatibility here describes protocol-level handling, not a guarantee that every browser displays the same error page. Older clients, embedded WebViews, proxies, and captive portals may impose additional behavior.

1xx — Informational responses

100

Continue

The server has accepted the request headers and is waiting for the remaining request body. It is commonly used with Expect: 100-continue so a client can avoid uploading a large body when the request will be rejected.

Operational guidance: Interim response; continue sending the body only when one is expected.

101

Switching Protocols

The server agrees to change the protocol for this connection after the client requests an upgrade. WebSocket handshakes are a familiar use.

Operational guidance: Connection-level transition; verify the Upgrade and Connection headers.

102

Processing

A WebDAV server reports that a lengthy operation has started but has not completed. It is a legacy/deprecated response and should not be mistaken for the final result.

Operational guidance: Interim WebDAV status; wait for the final response.

103

Early Hints

The server sends preliminary headers, often Link hints, while preparing the final response. A client may begin fetching likely critical assets early.

Operational guidance: Interim optimization; a final response must follow.

2xx — Successful responses

200

OK

The request succeeded. The representation depends on the method: GET returns the resource, HEAD returns metadata without a body, and a write action may return a result representation.

Operational guidance: Use for a completed request with a response representation when appropriate.

201

Created

The request completed and created one or more resources. The response should identify the new resource, commonly with Location, and may return its representation.

Operational guidance: Typical after POST or PUT; ensure the created resource can be located.

202

Accepted

The server accepted the request for processing, but processing has not finished and may still fail. HTTP does not later deliver a second response for the same exchange.

Operational guidance: Provide an operation/status URL or another way to learn the eventual outcome.

203

Non-Authoritative Information

A transforming proxy or intermediary returned metadata or content that differs from the origin response. It signals that the response is not a direct authoritative representation.

Operational guidance: Use only when an intermediary transformation is relevant.

204

No Content

The request succeeded and there is no response content to send. Headers can still carry useful metadata, such as updated validators.

Operational guidance: Do not include a response body.

205

Reset Content

The request succeeded and the client is instructed to reset the view or form that submitted it. No response content is sent.

Operational guidance: Useful for interactions that should clear/reset the current input state.

206

Partial Content

The server fulfilled a valid range request and returns only the requested byte range or ranges. Content-Range describes what was delivered.

Operational guidance: Ensure range and Content-Range values match; common for resumable media/downloads.

207

Multi-Status

A WebDAV response reports separate results for multiple resources or sub-operations, usually in a structured XML body.

Operational guidance: Interpret each embedded resource result; the outer status alone is not the full outcome.

208

Already Reported

A WebDAV multistatus response omits members already listed earlier in the same response to avoid repeating them.

Operational guidance: WebDAV-specific; interpret together with the surrounding multistatus response.

226

IM Used

The server fulfilled a GET using instance manipulations and returns a representation derived from the current resource according to the negotiated delta mechanism.

Operational guidance: Specialized delta encoding; clients and servers must agree on the transformation.

3xx — Redirection and cache validation

300

Multiple Choices

The target has multiple representations or destinations and the response offers choices. A client or user may select the preferred variant.

Operational guidance: Include clear alternatives; do not assume every client will choose automatically.

301

Moved Permanently

The resource has a lasting new URI. Clients may update stored links and caches, so use it only when the move is intended to persist.

Operational guidance: For SEO migrations, redirect directly to the final equivalent URL and update internal links.

302

Found

The resource is temporarily available at another URI. Historical behavior permits method changes in some cases, so it is not the safest choice when a POST must remain a POST.

Operational guidance: Use for temporary moves when method rewriting is acceptable; consider 307 when it is not.

303

See Other

The client should retrieve the resource named by Location with GET (or HEAD as appropriate), rather than repeat the original action. It is commonly used after a form submission.

Operational guidance: Implements the Post/Redirect/Get pattern and avoids resubmitting the action.

304

Not Modified

A conditional GET or HEAD indicates that the cached representation is still current. The response has no body and lets the client reuse its stored copy.

Operational guidance: Return only when a validator such as If-None-Match or If-Modified-Since matches.

305

Use Proxy

A historical response proposed that the client access the resource through a proxy. It is deprecated for security reasons and should not be used by modern services.

Operational guidance: Do not deploy; configure proxies out of band.

306

Unused

This value is reserved/unused in modern HTTP specifications. It has no standard operational meaning for a current web application.

Operational guidance: Do not send it.

307

Temporary Redirect

The resource is temporarily at another URI, and the client must preserve the original method and body when following the redirect.

Operational guidance: Use when temporary relocation must not turn POST into GET.

308

Permanent Redirect

The resource has permanently moved, and the client must preserve the original method and body when following the redirect.

Operational guidance: Use for lasting moves where method preservation matters; update canonical/internal references.

4xx — Client/request errors

400

Bad Request

The server cannot process the request because its syntax, framing, or supplied data is invalid. Repeating the same request unchanged is unlikely to help.

Operational guidance: Inspect URL encoding, JSON/body syntax, required fields, and request framing.

401

Unauthorized

The request lacks valid authentication credentials for the target. Despite its name, this response means authentication is required or failed.

Operational guidance: Send the expected credentials and include a WWW-Authenticate challenge.

402

Payment Required

Reserved for future use, though some products use it for payment or quota workflows. There is no single universally interoperable payment behavior.

Operational guidance: Treat vendor-specific meanings as such; document the API contract.

403

Forbidden

The server understood the request but refuses to fulfill it. Valid credentials do not necessarily change the outcome because the restriction may be policy-based.

Operational guidance: Check permissions, access policy, IP/WAF rules, and resource-level authorization.

404

Not Found

The server cannot find a current representation for the requested URI, or is unwilling to disclose that one exists. The response alone does not say whether absence is temporary or permanent.

Operational guidance: Repair the URL, restore the resource, or use 410 when removal is known to be permanent.

405

Method Not Allowed

The resource exists, but it does not support the method used in this request.

Operational guidance: Return an Allow header listing methods the resource accepts.

406

Not Acceptable

The server cannot produce a representation matching the client’s proactive Accept preferences.

Operational guidance: Relax Accept constraints or configure a suitable representation/negotiation policy.

407

Proxy Authentication Required

An intermediary proxy requires credentials before it will forward the request.

Operational guidance: Authenticate to the proxy using Proxy-Authenticate / Proxy-Authorization; this is distinct from origin authentication.

408

Request Timeout

The server did not receive the complete request in the time it was prepared to wait. The client may retry on a new connection.

Operational guidance: Check network stalls, upload size, and server/proxy timeout settings.

409

Conflict

The request conflicts with the current state of the resource, such as a version collision or an attempt to create a duplicate.

Operational guidance: Explain the conflict and provide enough current state for the client to resolve it.

410

Gone

The resource is intentionally and likely permanently unavailable, with no known replacement. This is stronger than a generic not-found response.

Operational guidance: Use when removal is deliberate; remove obsolete internal links and references.

411

Length Required

The server requires a Content-Length header but the request did not provide one.

Operational guidance: Send an accurate Content-Length or use a supported transfer framing.

412

Precondition Failed

A request condition such as If-Match evaluated to false, so the server did not perform the requested action.

Operational guidance: Refresh the representation and retry with current validators/state.

413

Content Too Large

The request body exceeds a limit the server is willing or able to process. The server may close the connection or allow retry after reducing the body.

Operational guidance: Reduce payload size or adjust documented upload limits.

414

URI Too Long

The request target is longer than the server is willing to interpret, often due to an oversized query string.

Operational guidance: Use a shorter URI or move suitable data into a request body.

415

Unsupported Media Type

The server refuses the request body because its media type, content encoding, or inspected format is unsupported.

Operational guidance: Send a supported Content-Type/encoding and a body matching it.

416

Range Not Satisfiable

The requested byte range cannot be served, for example because it starts beyond the representation length.

Operational guidance: Re-check resource length and range units; servers may return Content-Range: bytes */length.

417

Expectation Failed

The server or intermediary cannot meet an expectation declared in the Expect header.

Operational guidance: Retry without the unsupported expectation when safe and appropriate.

418

I'm a teapot

A humorous status originating in an April Fools’ specification. It is not a normal application error contract, although some services use it playfully.

Operational guidance: Do not depend on it for interoperable production behavior.

421

Misdirected Request

The request reached a server that cannot produce an authoritative response for the target URI, often because connection routing or HTTP authority does not match.

Operational guidance: Retry over a suitable connection and inspect Host/:authority, SNI, and proxy routing.

422

Unprocessable Content

The content type and syntax are understood, but the server cannot apply the instructions or validate the submitted content.

Operational guidance: Return actionable field-level validation details; correcting the payload may allow success.

423

Locked

A WebDAV resource is locked, so the requested method cannot be performed until the lock condition is resolved.

Operational guidance: Check lock ownership, timeout, and WebDAV lock-token handling.

424

Failed Dependency

A WebDAV operation failed because a required preceding operation in the same request sequence failed.

Operational guidance: Resolve the earlier failed action before retrying dependent operations.

425

Too Early

The server declines to process a request that may have been replayed during early data, to reduce replay risk.

Operational guidance: Retry after the connection is established without early data.

426

Upgrade Required

The server refuses the current protocol and indicates that the client should switch to another one.

Operational guidance: Include an Upgrade header that describes supported protocol choices.

428

Precondition Required

The server requires a conditional request to prevent lost updates, but the client sent an unconditional one.

Operational guidance: Fetch current state and submit an appropriate condition such as If-Match.

429

Too Many Requests

The client has sent too many requests in a given period, based on a server-defined rate limit.

Operational guidance: Back off, honor Retry-After when present, and avoid synchronized retry bursts.

431

Request Header Fields Too Large

The server will not process the request because one or more header fields, or the combined header set, is too large.

Operational guidance: Reduce cookies/custom headers or adjust an intentional server limit.

451

Unavailable For Legal Reasons

The server cannot provide the requested resource because of a legal restriction.

Operational guidance: Where appropriate, explain the restriction and its scope without exposing protected information.

5xx — Server and intermediary errors

500

Internal Server Error

The server encountered an unexpected condition and cannot complete the request. It is a general fallback when no more precise server error applies.

Operational guidance: Correlate the request with server logs and avoid exposing stack traces to visitors.

501

Not Implemented

The server does not support the functionality required to fulfill the request, commonly an unimplemented method or capability.

Operational guidance: Implement the capability or use a supported method; it is not intended for temporary overload.

502

Bad Gateway

A server acting as a gateway or proxy received an invalid response from an upstream server.

Operational guidance: Inspect upstream health, protocol/TLS settings, DNS, and proxy logs.

503

Service Unavailable

The server is temporarily unable to handle the request, often due to maintenance or overload.

Operational guidance: If possible provide Retry-After, a helpful response, and cache controls suitable for a temporary failure.

504

Gateway Timeout

A gateway or proxy did not receive a timely response from an upstream service.

Operational guidance: Investigate upstream latency, network paths, and timeout budgets across the chain.

505

HTTP Version Not Supported

The server does not support the major HTTP version used in the request.

Operational guidance: Use a supported protocol version or update server/proxy configuration.

506

Variant Also Negotiates

A server configuration error created a circular content-negotiation arrangement in which the selected variant negotiates again.

Operational guidance: Fix the variant/negotiation configuration; this is an origin-side fault.

507

Insufficient Storage

A WebDAV server cannot store the representation needed to complete the operation.

Operational guidance: Free or provision storage and check quotas before retrying.

508

Loop Detected

A server detected an infinite loop while processing a request, commonly during WebDAV binding traversal.

Operational guidance: Break the cyclic resource relationship or processing rule.

510

Not Extended

The request requires an extension that the server does not support.

Operational guidance: Use a supported extension set or negotiate an alternative.

511

Network Authentication Required

The client must authenticate to gain access to the network, typically at a captive portal. It is intended for network intermediaries, not an origin website login.

Operational guidance: Complete network access authentication, then retry the original request.

Notable non-standard and provider-specific responses

These values are seen in particular products, server logs, CDNs, or applications. They are not interchangeable with registered standard meanings; consult the generating service’s contract.

419

Authentication Timeout (non-standard)

Some applications use this label when an authentication session expires. It is not a universally assigned HTTP status, so clients cannot rely on consistent semantics.

Operational guidance: Refresh authentication according to the service contract.

420

Enhance Your Calm (non-standard)

A vendor-specific response historically used for throttling. Its meaning is implementation-defined.

Operational guidance: Follow documented rate-limit guidance.

444

Connection Closed (non-standard)

Some servers close the connection without sending a conventional response, often as a filtering measure.

Operational guidance: Check provider logs; clients may report a network error rather than display this code.

449

Retry With (non-standard)

A Microsoft extension used by some services to ask a client to retry with additional information.

Operational guidance: Follow the specific API documentation.

499

Client Closed Request (non-standard)

A reverse proxy may log this when the client disconnects before the upstream response is completed. It is usually a log classification rather than a response delivered to that client.

Operational guidance: Investigate client cancellations and slow upstream requests.

509

Bandwidth Limit Exceeded (non-standard)

Some hosting platforms use this code for a quota or bandwidth cap. It is not a general interoperable HTTP meaning.

Operational guidance: Check the host’s quota and billing configuration.

520

Web Server Returned an Unknown Error (vendor-specific)

A CDN or proxy may use this when it receives an unexpected or empty origin response.

Operational guidance: Compare edge and origin logs; verify the origin emits a valid HTTP response.

521

Web Server Is Down (vendor-specific)

A proxy could not establish a connection to the origin or the origin refused it.

Operational guidance: Check origin availability, firewall rules, and proxy allowlists.

522

Connection Timed Out (vendor-specific)

An edge service connected or attempted to connect to the origin but did not complete the exchange within its timeout.

Operational guidance: Review origin responsiveness and network latency.

523

Origin Is Unreachable (vendor-specific)

A proxy could not reach the configured origin address.

Operational guidance: Check DNS resolution, routing, and origin IP configuration.

524

A Timeout Occurred (vendor-specific)

The connection to the origin succeeded, but the origin did not send a timely HTTP response.

Operational guidance: Reduce origin processing time or adjust supported timeout settings.

525

SSL Handshake Failed (vendor-specific)

A proxy could not complete TLS negotiation with the origin.

Operational guidance: Validate certificates, protocol/cipher compatibility, and SNI.

526

Invalid SSL Certificate (vendor-specific)

An intermediary rejected the origin certificate during validation.

Operational guidance: Install a valid, correctly named, trusted, unexpired certificate and full chain.

527

Railgun Error (vendor-specific)

A legacy/vendor-specific proxy status reports a failure in an origin acceleration connection.

Operational guidance: Inspect the provider-specific connector and origin path.

598

Network Read Timeout (non-standard)

Some clients or proxies use this value to describe a network read timeout. It has no universal HTTP meaning.

Operational guidance: Inspect the client/proxy diagnostics.

599

Network Connect Timeout (non-standard)

Some proxies use this value when a network connection attempt times out. Its meaning depends on the implementation.

Operational guidance: Check reachability and timeout settings.

Using status codes in redirect and SEO audits

For a permanent URL move, use a permanent redirect only when the destination is intended to replace the old URL; for a temporary change, select a temporary response. Keep chains short and point to the final equivalent destination. Confirm that each Location value resolves, that the final response is appropriate, and that canonical tags and internal links agree with the intended URL. A 2xx at the end confirms an HTTP success response, not that the page is useful, indexable, or technically healthy.