HTTP Status Code Lookup
What a status code means, which RFC defines it, and what to do next.
Enter a status code on the left.
How it works
Every code here cites RFC 9110 where RFC 9110 defines it. That matters more than it sounds: RFC 2616 was obsoleted in 2014, the RFC 7230–7235 series that replaced it was itself obsoleted in June 2022, and a reference still quoting 2616 is quoting a specification superseded twice.
401 and 403 are named backwards
401 Unauthorized actually means unauthenticated — no credentials, or bad ones — and it must carry
a WWW-Authenticate header saying how to fix that. 403 Forbidden means you were
identified and still may not do this, so retrying with the same credentials will never work. Where acknowledging a
resource exists is itself a disclosure, 404 is the better answer than 403.
400 or 422
400 means the server could not parse the request — malformed JSON, a broken header. 422 means it parsed fine and then failed validation: well-formed, semantically wrong. The practical test is which layer rejected it, a parser or your own rules.
Caching is a property of the code
Several codes are heuristically cacheable by default under RFC 9110 §15.1, even with no Cache-Control
at all — 200, 301, 404 and 410 among them. That is why a wrongly-served 301 is so hard to take back: it may be
cached indefinitely by clients you will never reach. An explicit directive always wins, and this field describes
the default in its absence.
418 is not real
It comes from the Hyper Text Coffee Pot Control Protocol, an April Fools RFC from 1998. It is kept as reserved in the IANA registry so nobody assigns 418 to anything — which is a different thing from being a code you should return.
Example
429 should carry Retry-After; a client that ignores it and retries immediately is
exactly the behaviour the code exists to signal. 503 with Retry-After is the correct
response for planned maintenance — it stops a crawler treating the outage as removal. 451 takes its
number from Fahrenheit 451.
Frequently asked questions
Why does this cite RFC 9110 rather than RFC 2616?
Because RFC 2616 was obsoleted in 2014 and the RFC 7230-7235 series that replaced it was itself obsoleted by RFC 9110 in June 2022. A reference still citing 2616 is quoting a specification that has been superseded twice, which matters when the wording is what you are relying on.
What is the difference between 401 and 403?
401 means the request was not authenticated — no credentials, or bad ones — and it must carry a WWW-Authenticate header saying how to fix that. 403 means you were identified and still may not do this, so retrying with the same credentials will never work. The names are backwards from what they do: 401 says Unauthorized but means unauthenticated.
When should a server return 422 instead of 400?
400 means the server could not parse the request at all — malformed JSON, a broken header. 422 means it parsed fine and then failed validation: well-formed, semantically wrong. The practical test is whether a parser or your own business rules rejected it.
Is 418 a real status code?
No. It comes from the Hyper Text Coffee Pot Control Protocol, an April Fools RFC from 1998. It is kept as reserved in the IANA registry specifically so that nobody assigns 418 to anything real, which is a slightly different thing from being a status code you should return.
Related tools
Common Ports Lookup
Look up what normally listens on a TCP or UDP port, and why it matters if it is exposed.
LocalURL Parser
Split a URL into scheme, host, path, query and fragment.
LocalJSON Formatter & Validator
Format, validate and measure JSON, with errors located by line and column.
LocalDNS Lookup
Query A, AAAA, MX, TXT, NS, CNAME, SOA and CAA records for any domain.
Sends dataWHOIS Lookup
Registrar, registration and expiry dates, status codes and name servers for any domain.
Sends dataPort Checker
Check whether one well-known port on a host answers — open, closed, or timed out.
Sends data