Free Tools/No signup required

HTTP Status Code Reference

Complete searchable HTTP status code reference with descriptions, use cases, and monitoring tips for each code.

100
Continue
Server received request headers; client should proceed with body
101
Switching Protocols
Server is switching protocols as requested (e.g. WebSocket upgrade)
103
Early Hints
Lets the browser preload resources while the server prepares a response
200
OK
Request succeeded. The meaning depends on the HTTP method used
💡 Your health check endpoint should return 200 when the service is healthy
201
Created
Request succeeded and a new resource was created (common for POST)
202
Accepted
Request accepted for processing but not yet completed (async operations)
204
No Content
Request succeeded but there is no content to return (common for DELETE)
206
Partial Content
Server is delivering part of the resource due to a Range header
301
Moved Permanently
Resource has permanently moved to a new URL. Search engines transfer ranking
💡 Alert if your main URLs start returning 301s unexpectedly — may indicate misconfiguration
302
Found
Temporary redirect. Client should continue using the original URL
304
Not Modified
Resource hasn't changed since last request. Use cached version
307
Temporary Redirect
Like 302 but guarantees method and body won't change in the redirect
308
Permanent Redirect
Like 301 but guarantees method and body won't change in the redirect
400
Bad Request
Server cannot process the request due to client error (malformed syntax, invalid parameters)
💡 A spike in 400s may indicate a broken client deployment or API contract change
401
Unauthorized
Authentication is required. The request lacks valid credentials
💡 Mass 401s can signal expired API keys or auth service outage
403
Forbidden
Server understood the request but refuses to authorize it
404
Not Found
Server cannot find the requested resource. The URL is not recognized
💡 Monitor 404 rate on critical paths — broken links hurt SEO and user experience
405
Method Not Allowed
The HTTP method is not supported for this resource
408
Request Timeout
Server timed out waiting for the request
409
Conflict
Request conflicts with the current state of the resource (concurrent edits)
410
Gone
Resource has been permanently deleted. Unlike 404, this is intentional
413
Payload Too Large
Request entity exceeds the server's defined limits
415
Unsupported Media Type
The media format of the request is not supported
422
Unprocessable Entity
Request is well-formed but semantically invalid (validation errors)
429
Too Many Requests
Client has sent too many requests in a given timeframe (rate limiting)
💡 Critical to monitor — indicates you're hitting API rate limits or being rate-limited by upstream
500
Internal Server Error
Generic server error. Something unexpected went wrong on the server
💡 Any 500 in production deserves investigation. Alert immediately on elevated rates
502
Bad Gateway
Server acting as gateway received an invalid response from upstream
💡 Often indicates upstream service is down or overloaded. Check reverse proxy → backend connectivity
503
Service Unavailable
Server is temporarily unable to handle the request (overloaded or in maintenance)
💡 Expected during deploys. Unexpected 503s mean capacity issues or health check failures
504
Gateway Timeout
Server acting as gateway didn't receive a timely response from upstream
💡 Signals upstream latency. Check database queries, external API calls, or network issues
507
Insufficient Storage
Server cannot store the representation needed to complete the request
508
Loop Detected
Server detected an infinite loop while processing the request
511
Network Authentication Required
Client needs to authenticate to gain network access (captive portals)
Showing 32 of 32 status codes

Frequently Asked Questions

At minimum: 5xx error rate (any elevated rate is a problem), 4xx rate (spikes indicate broken clients or attacks), response time (latency increases often precede errors), and specific codes like 429 (rate limiting) and 503 (capacity). Set up alerts for sustained 5xx rates above your baseline.

401 Unauthorized means 'I don't know who you are' — the request lacks valid authentication credentials. 403 Forbidden means 'I know who you are, but you're not allowed' — authentication succeeded but authorization failed.

Return 404 when the resource doesn't exist or you don't want to reveal whether it exists. Return 410 when the resource was intentionally and permanently deleted — this tells search engines to remove it from their index faster than a 404.

A 502 means your reverse proxy (Nginx, Cloudflare, load balancer) couldn't get a valid response from the upstream server. Common causes: upstream crashed, connection refused, upstream returned malformed response, or network issues between proxy and backend.

Related tools

Need continuous monitoring?

A one-time check is helpful, but 24/7 monitoring catches issues the moment they happen. DevHelm monitors your services every 30 seconds from 4 global regions — free tier includes 50 monitors.

Start Monitoring Free