HTTP Status Code Lookup
71 status codes
100Continue
The server received the request headers and the client should send the body. Sent in reply to Expect: 100-continue, so large uploads can be rejected before they're sent.
InformationalRFC 9110HttpStatus.CONTINUE101Switching Protocols
The server is switching to the protocol the client asked for in the Upgrade header, most often WebSocket.
InformationalRFC 9110HttpStatus.SWITCHING_PROTOCOLS102ProcessingDeprecated
WebDAV: the server is still working on a long request, to stop the client timing out. Removed from later WebDAV specs.
InformationalRFC 2518HttpStatus.PROCESSING103Early Hints
Sent before the final response with Link headers, so the browser can start preloading stylesheets and scripts while the server prepares the page.
InformationalRFC 8297HttpStatus.EARLY_HINTS200OK
The request succeeded. The body contains the result: the resource for GET, the outcome for POST.
SuccessRFC 9110HttpStatus.OK201Created
A new resource was created, typically by POST or PUT. Include a Location header with its URL.
SuccessRFC 9110HttpStatus.CREATED202Accepted
The request was accepted for processing, but isn't finished (e.g. queued as a background job). Often returned with a link to check the job's status.
SuccessRFC 9110HttpStatus.ACCEPTED203Non-Authoritative Information
Success, but a proxy modified the response from the origin server.
SuccessRFC 9110HttpStatus.NON_AUTHORITATIVE_INFORMATION204No Content
Success with no body. Common for DELETE, and for PUT or PATCH when the updated resource isn't returned.
SuccessRFC 9110HttpStatus.NO_CONTENT205Reset Content
Success; the client should reset the form or view that sent the request. Rarely used.
SuccessRFC 9110HttpStatus.RESET_CONTENT206Partial Content
The body is only part of the resource, as requested by a Range header. Used for resumable downloads and video seeking.
SuccessRFC 9110HttpStatus.PARTIAL_CONTENT207Multi-Status
WebDAV: the body (usually XML) holds a separate status for each of several resources.
SuccessRFC 4918HttpStatus.MULTI_STATUS208Already Reported
WebDAV: members of a binding were already listed earlier in the same Multi-Status response.
SuccessRFC 5842HttpStatus.ALREADY_REPORTED226IM Used
The response is the result of instance manipulations (delta encoding) applied to the resource. Rarely seen.
SuccessRFC 3229HttpStatus.IM_USED300Multiple Choices
Several representations are available and the client (or user) should choose one. Rarely used in practice.
RedirectionRFC 9110HttpStatus.MULTIPLE_CHOICES301Moved Permanently
A permanent redirect: the resource has a new URL, given in Location. Search engines move ranking to the new URL; browsers cache it. Clients may change POST to GET when following it; use 308 to keep the method.
RedirectionRFC 9110HttpStatus.MOVED_PERMANENTLY302Found
A temporary redirect to another URL (Location). Clients may change POST to GET when following it; use 307 to keep the method, or 303 to require GET.
RedirectionRFC 9110HttpStatus.FOUND303See Other
Fetch the result with GET at another URL. The classic Post/Redirect/Get pattern after a form submission.
RedirectionRFC 9110HttpStatus.SEE_OTHER304Not Modified
Reply to a conditional request (If-None-Match or If-Modified-Since): the cached copy is still valid, so no body is sent.
RedirectionRFC 9110HttpStatus.NOT_MODIFIED305Use ProxyDeprecated
Deprecated for security reasons: told the client to use a proxy. Don't use it.
RedirectionRFC 9110HttpStatus.USE_PROXY307Temporary Redirect
The resource is temporarily at another URL, and the client must repeat the request with the same method and body.
RedirectionRFC 9110HttpStatus.TEMPORARY_REDIRECT308Permanent Redirect
Like 301, but the method and body must not change, so a POST stays a POST.
RedirectionRFC 9110HttpStatus.PERMANENT_REDIRECT400Bad Request
The request is malformed: invalid JSON, a missing required parameter, a bad value. Don't retry without changing it. Spring returns it for failed @Valid validation and unreadable bodies.
Client errorRFC 9110HttpStatus.BAD_REQUEST401Unauthorized
Authentication is missing or invalid, e.g. no token, or an expired one. Must include WWW-Authenticate. Despite the name it's about authentication; use 403 when the user is known but not allowed.
Client errorRFC 9110HttpStatus.UNAUTHORIZED402Payment Required
Reserved for future use; some APIs use it when a subscription or quota has to be paid for.
Client errorRFC 9110HttpStatus.PAYMENT_REQUIRED403Forbidden
The server knows who you are but won't allow this, e.g. a missing role or scope. Logging in again won't help. Also what Spring Security returns for a failed CSRF check.
Client errorRFC 9110HttpStatus.FORBIDDEN404Not Found
Nothing exists at this URL, or the server won't say whether it does (hiding a resource from users who may not see it).
Client errorRFC 9110HttpStatus.NOT_FOUND405Method Not Allowed
The URL exists but doesn't support this method, e.g. DELETE on a read-only endpoint. The Allow header lists the methods that work.
Client errorRFC 9110HttpStatus.METHOD_NOT_ALLOWED406Not Acceptable
The server can't produce any format listed in the Accept header, e.g. only JSON is available but the client asked for XML.
Client errorRFC 9110HttpStatus.NOT_ACCEPTABLE407Proxy Authentication Required
Like 401, but the proxy in between needs credentials (Proxy-Authenticate / Proxy-Authorization).
Client errorRFC 9110HttpStatus.PROXY_AUTHENTICATION_REQUIRED408Request Timeout
The client took too long to send the request, so the server closed the connection. Safe to retry.
Client errorRFC 9110HttpStatus.REQUEST_TIMEOUT409Conflict
The request conflicts with the resource's current state: a duplicate username, an edit based on a stale version (optimistic locking), a unique constraint.
Client errorRFC 9110HttpStatus.CONFLICT410Gone
The resource existed but was removed on purpose and won't come back. Search engines drop it faster than a 404.
Client errorRFC 9110HttpStatus.GONE411Length Required
The server requires a Content-Length header.
Client errorRFC 9110HttpStatus.LENGTH_REQUIRED412Precondition Failed
A condition in the request headers wasn't met, typically If-Match with an outdated ETag: someone else changed the resource first.
Client errorRFC 9110HttpStatus.PRECONDITION_FAILED413Content Too Large
The body is bigger than the server accepts, e.g. an upload over nginx's client_max_body_size or Spring's spring.servlet.multipart.max-file-size.
Client errorRFC 9110HttpStatus.PAYLOAD_TOO_LARGE414URI Too Long
The URL is longer than the server will handle, often a GET with a huge query string that should be a POST.
Client errorRFC 9110HttpStatus.URI_TOO_LONG415Unsupported Media Type
The body's format isn't accepted, usually a missing or wrong Content-Type, e.g. JSON sent without Content-Type: application/json.
Client errorRFC 9110HttpStatus.UNSUPPORTED_MEDIA_TYPE416Range Not Satisfiable
The Range header asks for bytes outside the resource.
Client errorRFC 9110HttpStatus.REQUESTED_RANGE_NOT_SATISFIABLE417Expectation Failed
The server can't meet the Expect header, usually Expect: 100-continue.
Client errorRFC 9110HttpStatus.EXPECTATION_FAILED418I'm a teapot
An April Fools' joke (the Hyper Text Coffee Pot Control Protocol): the server refuses to brew coffee because it's a teapot. Reserved, and sometimes used for requests a server deliberately refuses.
Client errorRFC 2324HttpStatus.I_AM_A_TEAPOT421Misdirected Request
The request reached a server that can't answer for this host, e.g. an HTTP/2 connection reused for a domain its certificate covers but the server doesn't serve.
Client errorRFC 9110422Unprocessable Content
The request is well-formed but semantically invalid, e.g. valid JSON that fails business rules. Many APIs use it for validation errors instead of 400.
Client errorRFC 9110HttpStatus.UNPROCESSABLE_ENTITY423Locked
WebDAV: the resource is locked.
Client errorRFC 4918HttpStatus.LOCKED424Failed Dependency
WebDAV: the request failed because an earlier request it depended on failed.
Client errorRFC 4918HttpStatus.FAILED_DEPENDENCY425Too Early
The server won't process a request sent as TLS early data (0-RTT), because it might be replayed.
Client errorRFC 8470HttpStatus.TOO_EARLY426Upgrade Required
The client must switch to another protocol (given in Upgrade), e.g. a newer TLS or HTTP version.
Client errorRFC 9110HttpStatus.UPGRADE_REQUIRED428Precondition Required
The server requires conditional requests (If-Match) to prevent lost updates, and this one had none.
Client errorRFC 6585HttpStatus.PRECONDITION_REQUIRED429Too Many Requests
Rate limit exceeded. Retry after the time given in Retry-After, ideally with exponential backoff.
Client errorRFC 6585HttpStatus.TOO_MANY_REQUESTS431Request Header Fields Too Large
The headers are too big, most often too many or too large cookies, or a huge JWT in Authorization.
Client errorRFC 6585HttpStatus.REQUEST_HEADER_FIELDS_TOO_LARGE444No ResponseUnofficial · nginx
nginx closed the connection without sending anything, typically to drop unwanted or malicious requests. Only visible in nginx's logs.
Client errornginx451Unavailable For Legal Reasons
Blocked for legal reasons, such as a court order or government censorship. Named after Fahrenheit 451.
Client errorRFC 7725HttpStatus.UNAVAILABLE_FOR_LEGAL_REASONS499Client Closed RequestUnofficial · nginx
nginx: the client closed the connection before the server answered, e.g. the user navigated away or a client timeout was shorter than the backend's response time.
Client errornginx500Internal Server Error
An unexpected error on the server, typically an unhandled exception. Check the server logs for the stack trace.
Server errorRFC 9110HttpStatus.INTERNAL_SERVER_ERROR501Not Implemented
The server doesn't support the functionality needed, e.g. an HTTP method it doesn't recognize.
Server errorRFC 9110HttpStatus.NOT_IMPLEMENTED502Bad Gateway
A proxy or gateway (nginx, a load balancer, an API gateway) got an invalid response from the upstream server, often because it crashed or closed the connection. Usually safe to retry.
Server errorRFC 9110HttpStatus.BAD_GATEWAY503Service Unavailable
The server is temporarily unable to handle requests: overloaded, down for maintenance, or no healthy backends. Retry later, respecting Retry-After.
Server errorRFC 9110HttpStatus.SERVICE_UNAVAILABLE504Gateway Timeout
A proxy or gateway didn't get a response from the upstream server in time, e.g. a slow database query behind nginx's proxy_read_timeout.
Server errorRFC 9110HttpStatus.GATEWAY_TIMEOUT505HTTP Version Not Supported
The server doesn't support the HTTP version of the request.
Server errorRFC 9110HttpStatus.HTTP_VERSION_NOT_SUPPORTED506Variant Also Negotiates
A content negotiation configuration error on the server. Rarely seen.
Server errorRFC 2295HttpStatus.VARIANT_ALSO_NEGOTIATES507Insufficient Storage
WebDAV: the server can't store what's needed to complete the request.
Server errorRFC 4918HttpStatus.INSUFFICIENT_STORAGE508Loop Detected
WebDAV: the server found an infinite loop while processing the request.
Server errorRFC 5842HttpStatus.LOOP_DETECTED510Not ExtendedDeprecated
Further extensions to the request are required. Obsolete.
Server errorRFC 2774HttpStatus.NOT_EXTENDED511Network Authentication Required
You need to sign in to the network first, e.g. a hotel or airport Wi-Fi captive portal.
Server errorRFC 6585HttpStatus.NETWORK_AUTHENTICATION_REQUIRED520Web Server Returned an Unknown ErrorUnofficial · Cloudflare
Cloudflare: the origin server returned an empty, unknown or unexpected response.
Server errorCloudflare521Web Server Is DownUnofficial · Cloudflare
Cloudflare: the origin server refused the connection. The server is down or a firewall blocks Cloudflare's IP ranges.
Server errorCloudflare522Connection Timed OutUnofficial · Cloudflare
Cloudflare couldn't establish a TCP connection to the origin in time: the origin is overloaded or unreachable.
Server errorCloudflare523Origin Is UnreachableUnofficial · Cloudflare
Cloudflare can't reach the origin, often because of wrong DNS records or network routing problems.
Server errorCloudflare524A Timeout OccurredUnofficial · Cloudflare
Cloudflare connected to the origin, but it didn't send a response within 100 seconds (by default). Move long work to a background job.
Server errorCloudflare525SSL Handshake FailedUnofficial · Cloudflare
Cloudflare couldn't complete a TLS handshake with the origin, e.g. no certificate or unsupported ciphers.
Server errorCloudflare526Invalid SSL CertificateUnofficial · Cloudflare
With Full (strict) SSL, Cloudflare couldn't validate the origin's certificate: expired, self-signed or for another hostname.
Server errorCloudflare
Look up HTTP status codes with clear descriptions and typical causes.
How to use the HTTP Status Code Lookup
- Type a code (like 429), part of one (like 5 for all server errors), or words (like "timeout").
- Filter by class to browse, for example, every redirect.
- Copy the Spring
HttpStatusconstant for your controller or test.
The five classes
- 1xx Informational: an interim response; the final one follows.
- 2xx Success: the request worked.
- 3xx Redirection: go somewhere else, or use your cached copy.
- 4xx Client error: the request is wrong; retrying it unchanged won't help (except 408 and 429).
- 5xx Server error: the server failed; retrying later may work.
Codes people mix up
- 401 vs 403: 401 means "who are you?" (log in); 403 means "I know who you are, and no".
- 400 vs 422: 400 for requests that can't be parsed; many APIs use 422 for valid JSON that fails validation.
- 301/302 vs 308/307: the newer pair guarantees the method stays the same, so a redirected POST isn't turned into a GET.
- 502 vs 504: both come from a proxy; 502 means the upstream answered badly, 504 that it didn't answer in time.
Frequently asked questions
What are the unofficial codes?
Codes outside the IANA registry that you'll still meet: nginx's 444 and 499 (in its logs), and Cloudflare's 520–526, which describe problems between Cloudflare and your origin server.
How do I return a status in Spring?
ResponseEntity.status(HttpStatus.CONFLICT).body(error), @ResponseStatus(HttpStatus.NOT_FOUND) on an exception class, or throw new ResponseStatusException(HttpStatus.FORBIDDEN).
Related tools
All tools- HTTP Header AnalyzerPaste raw HTTP headers to see what each one does and its security implications.
- cURL GeneratorBuild cURL commands from a method, URL, headers, body and authentication.
- CORS Header GeneratorGenerate CORS configuration for Spring Boot, Nginx, Express and Apache.
- URL ParserBreak a URL into protocol, credentials, host, port, path, query and fragment.
- Query String ParserTurn query strings into key/value tables and JSON into query strings.