Skip to main content
QUIETLYTIC
Networking

HTTP Status Code Lookup

What a status code means, which RFC defines it, and what to do next.

Local · nothing leaves this browser 61 codes indexed
Esc Clear
Meaning, specification and caching

Enter a status code on the left.

How it works

Every code here cites RFC 9110 where RFC 9110 defines it. That matters more than it sounds: RFC 2616 was obsoleted in 2014, the RFC 7230–7235 series that replaced it was itself obsoleted in June 2022, and a reference still quoting 2616 is quoting a specification superseded twice.

401 and 403 are named backwards

401 Unauthorized actually means unauthenticated — no credentials, or bad ones — and it must carry a WWW-Authenticate header saying how to fix that. 403 Forbidden means you were identified and still may not do this, so retrying with the same credentials will never work. Where acknowledging a resource exists is itself a disclosure, 404 is the better answer than 403.

400 or 422

400 means the server could not parse the request — malformed JSON, a broken header. 422 means it parsed fine and then failed validation: well-formed, semantically wrong. The practical test is which layer rejected it, a parser or your own rules.

Caching is a property of the code

Several codes are heuristically cacheable by default under RFC 9110 §15.1, even with no Cache-Control at all — 200, 301, 404 and 410 among them. That is why a wrongly-served 301 is so hard to take back: it may be cached indefinitely by clients you will never reach. An explicit directive always wins, and this field describes the default in its absence.

418 is not real

It comes from the Hyper Text Coffee Pot Control Protocol, an April Fools RFC from 1998. It is kept as reserved in the IANA registry so nobody assigns 418 to anything — which is a different thing from being a code you should return.

Example

429 should carry Retry-After; a client that ignores it and retries immediately is exactly the behaviour the code exists to signal. 503 with Retry-After is the correct response for planned maintenance — it stops a crawler treating the outage as removal. 451 takes its number from Fahrenheit 451.

Frequently asked questions

Why does this cite RFC 9110 rather than RFC 2616?

Because RFC 2616 was obsoleted in 2014 and the RFC 7230-7235 series that replaced it was itself obsoleted by RFC 9110 in June 2022. A reference still citing 2616 is quoting a specification that has been superseded twice, which matters when the wording is what you are relying on.

What is the difference between 401 and 403?

401 means the request was not authenticated — no credentials, or bad ones — and it must carry a WWW-Authenticate header saying how to fix that. 403 means you were identified and still may not do this, so retrying with the same credentials will never work. The names are backwards from what they do: 401 says Unauthorized but means unauthenticated.

When should a server return 422 instead of 400?

400 means the server could not parse the request at all — malformed JSON, a broken header. 422 means it parsed fine and then failed validation: well-formed, semantically wrong. The practical test is whether a parser or your own business rules rejected it.

Is 418 a real status code?

No. It comes from the Hyper Text Coffee Pot Control Protocol, an April Fools RFC from 1998. It is kept as reserved in the IANA registry specifically so that nobody assigns 418 to anything real, which is a slightly different thing from being a status code you should return.

Related tools

From the intelligence desk