Every response starts with a three-digit status code whose first digit gives its class: 1xx informational, 2xx success, 3xx redirection, 4xx client error, 5xx server error. A client treats an unknown code like the x00 code of its class, so an unfamiliar 499 is handled as 400.
| Status codes | Meaning in practice |
|---|---|
| 101 Switching Protocols, 103 Early Hints | WebSocket upgrade; early preload hints |
| 200 OK, 201 Created, 204 No Content | Success; new resource; empty body |
| 206 Partial Content | Answer to a Range request |
| 301 Moved Permanently, 308 Permanent Redirect | Permanent move; 308 keeps the method |
| 302 Found, 307 Temporary Redirect | Temporary move; 307 keeps the method |
| 303 See Other, 304 Not Modified | GET after POST; cached copy valid |
| 400 Bad Request, 422 Unprocessable Content | Malformed; well-formed but invalid |
| 401 Unauthorized, 403 Forbidden | Not logged in; logged in but not allowed |
| 404 Not Found, 410 Gone | Missing; permanently removed |
| 405 Method Not Allowed, 415 Unsupported Media Type | See Allow; wrong Content-Type |
| 429 Too Many Requests | Rate limited; see Retry-After |
| 500 Internal Server Error, 503 Service Unavailable | Server bug; overloaded or down |
| 502 Bad Gateway, 504 Gateway Timeout | Proxy got a bad or no upstream reply |
For 301 and 302, browsers historically turned a POST into a GET on the redirected request, which RFC 9110 still allows; 307 and 308 forbid it. Answering a form POST with 303 (the Post/Redirect/Get pattern) stops a reload from submitting twice. RFC 9110 (2022) renamed 413 "Payload Too Large" and 422 "Unprocessable Entity" to the names above, and reserved 418 "I'm a teapot", an April Fools' joke from RFC 2324.