What this does
A filterable reference for the 55 HTTP response codes you actually meet in production, each with its official name, category and a one-line summary of what it means. The whole table ships with the page — there is no lookup request, and no URL is fetched on your behalf, so it works with the network off.
How do I search it?
One box, three ways to match. Type digits and it filters on the code as a
substring, so 40 brings back the whole 400-block. Type words
and it matches the name — teapot lands on 418 alone. It also
searches the summaries, which is the useful one: cache surfaces
304, proxy surfaces 407 and 502. Clear the box to see
everything in numeric order.
What do the five categories mean?
The leading digit is the class, and it is colour-coded in the list:
- 1xx Informational — interim responses like the 101 WebSocket upgrade or 103 Early Hints. You rarely handle these yourself.
- 2xx Success — the request worked. 200, plus 201 Created and 204 No Content for APIs.
- 3xx Redirection — the answer is elsewhere, or your cache is still good.
- 4xx Client error — the request was wrong. This is the biggest group here, 27 codes.
- 5xx Server error — the request was reasonable and the server failed anyway.
What is the difference between 401 and 403?
401 Unauthorized means authentication is missing or failed —
the name is a historical misnomer, since it is about who you are, not what
you may do. 403 Forbidden means the server knows who you are
and is still refusing. As a rule: if presenting a valid credential would
change the answer, send 401; if it would not, send 403.
Which redirect code should I use?
301 and 308 are permanent, so browsers and search engines cache them; 302 and 307 are temporary. The difference within each pair is method handling: 307 and 308 guarantee the original method and body are preserved, while historically 301 and 302 let clients downgrade a POST to a GET.
POST /old → 301 Location: /new client may retry as GET /new
POST /old → 308 Location: /new client must retry as POST /new Use 303 See Other deliberately after a form POST, when redirecting to a GET result page is exactly what you want.
Which codes are not listed?
Deprecated and near-extinct ones: 305 and 306, plus some of the rarer WebDAV and extension codes. What is included covers the standard range through the useful oddities — 425 Too Early, 428 Precondition Required, 451 Unavailable For Legal Reasons, and yes, 418 I'm a teapot, which comes from an RFC 2324 April Fools joke and should never appear in a real API.
Related: URL encoder/decoder for escaping the paths in a Location header, JWT decoder when chasing down a 401, and CIDR calculator for the IP allowlist behind a 403.