What's the difference between 401 and 403?
401 Unauthorized means you're not authenticated (missing/invalid credentials); 403 Forbidden means you are authenticated but lack permission.
Showing 48 of 83 matching entries — narrow the search to see the rest.
204 is the same success with no body at all, used when there is nothing to send back.
202 means the work was only accepted, not finished — a 200 says the result is in this response.
Every code in the lookup above, grouped by class and by source. Standard codes come from the IANA registry; the nginx, Cloudflare, and unofficial sections cover codes you meet in logs and error pages that are not part of any RFC.
Find common HTTP response codes, meanings, and usage details.
Covers every code in the IANA registry plus the vendor codes you meet in real logs: nginx (444, 499), Cloudflare (520–527, 530), and unofficial ones such as 419 and 420. Search matches the code, the name, the class, the vendor, or the description — typing 5xx lists every server error, cloudflare lists the edge codes, and rate limit finds 429. Every code has its own shareable link (?code=404), the full list is below, and the FAQ untangles the pairs that get mixed up most — 301 vs 302, 401 vs 403, 502 vs 504.
401 Unauthorized means you're not authenticated (missing/invalid credentials); 403 Forbidden means you are authenticated but lack permission.
301 Moved Permanently means the URL has changed for good, so clients and search engines should switch to the new one. 302 Found is temporary — the client should keep using the original URL next time.
200 OK returns a response body along with the success. 204 No Content confirms success with no body at all — common for a successful DELETE or an update with nothing new to send back.
500 Internal Server Error means the server hit an unexpected bug or unhandled exception. 503 Service Unavailable is a deliberate, usually temporary state — overload, maintenance, or a dependency outage — often paired with a Retry-After header.
Too Many Requests — the client has exceeded a rate limit set by the server.
No — this is a static reference lookup against a curated list of status codes and their meanings, not a live checker. To see what code a real URL returns, use your browser's DevTools Network tab or run curl -I <url>.
Yes by spec, but some APIs misuse 200 with an error code buried in the response body — this breaks HTTP semantics and confuses monitoring tools.
No — entirely client-side reference lookup.