Searchable HTTP status code reference. Find what 200, 301, 401, 404, 429, 500 and every common code mean. Instant, client-side filter.
This is a fast, searchable reference for every HTTP status code you'll meet in real backend, API, or frontend work. Type any digit, partial word, or category and the list filters live. Everything runs in your browser — no requests are sent anywhere.
HTTP responses always include a three-digit status code. The first digit assigns the response to one of five classes:
In day-to-day API work the codes you'll write conditionals against are a small subset: 200, 201, 204, 301, 302, 304, 400, 401, 403, 404, 409, 422, 429, 500, 502, 503, 504. Knowing the distinction between each pair (200 vs 201, 401 vs 403, 502 vs 504) is what separates a junior REST consumer from someone who can debug production incidents.
If you're designing an API, pick the most specific code that fits. Returning 200 OK with { "error": "…" } in the body is an antipattern — clients, monitoring tools, and HTTP intermediaries cannot tell the response failed. Use 4xx for client mistakes, 5xx for your bugs, and include a machine-readable error body alongside the right status code.
1xx is informational (rarely seen by users), 2xx means success, 3xx means redirection, 4xx is a client-side error (bad request, missing auth, wrong URL), and 5xx is a server-side error. The first digit alone tells you whose 'fault' the response is.
401 Unauthorized means the request lacks valid authentication — log in or send a token. 403 Forbidden means you are authenticated but not allowed to access this resource. 401 = who are you? 403 = I know who you are and you can't have it.
Use 301 Moved Permanently for permanent redirects (URL changes, domain moves) — search engines transfer ranking signals. Use 302 Found for temporary redirects (A/B tests, maintenance pages) — search engines keep indexing the original.
Your client is being rate-limited. The server is rejecting requests because you sent too many in a short window. Look for a Retry-After header which tells you how long to wait before retrying.
Most are defined in RFC 7231, RFC 7232, and related IETF documents. Some (like 418 I'm a teapot) come from RFC 2324, an April Fools' joke that became canonical. A few like Cloudflare's 521-525 are non-standard.
Browse all free tools · Guides and tutorials · PDF tools · Developer tools · Text tools · SEO tools