Skip to content

HTTP Status Code Lookup

A searchable reference for HTTP status codes — not just the official one-line name, but the extra context for the pairs everyone mixes up: 401 vs 403, 502 vs 503 vs 504, 301 vs 307.

  • Search by code or by keyword
  • All five status classes, 1xx–5xx
  • Extra context for the confusing pairs
  • No network request — the table ships with the page

Reference

No lookups leave your browser

    How to look up an HTTP status code

    1. 01

      Type a number or a word

      Enter a status code like 404, a partial code like 5 to see the whole 5xx class, or a word like "gateway" or "unauthorized".

    2. 02

      Read the summary

      Every code gets a plain-language, one-sentence explanation of what it actually means.

    3. 03

      Check the extra context where it exists

      Codes that are commonly confused with a neighbor — 401/403, 502/503/504, 301/307 — get a longer note explaining the actual difference.

    The five classes, in one sentence each#

    1xx (Informational) — the request is still being processed; rare to see directly, since browsers handle these automatically. 2xx (Success) — the request worked. 3xx (Redirection) — more steps are needed to complete the request, usually because the resource moved. 4xx (Client error) — something about the request itself was wrong. 5xx (Server error) — the request was probably fine; the server failed to handle it.

    The class alone tells you where to start looking: a 4xx means check what you sent, a 5xx means check what the server did with it.

    401 versus 403: authentication versus authorization#

    This is the pair that gets swapped most often. 401 Unauthorized genuinely means "unauthenticated" — the server does not know who you are yet, and per spec must include a WWW-Authenticate header explaining how to log in. 403 Forbidden means the server does know who you are, and the answer is still no.

    A login page correctly returns 401 to an unauthenticated visitor. An authenticated user trying to access someone else's private data should get 403, not 401 — they are logged in; they are just not allowed to see that particular thing.

    502, 503 and 504: who actually failed#

    All three sound like "the server is broken," but they point at different things. 502 Bad Gateway means a proxy or load balancer got a garbled or invalid response from the application server behind it — the upstream is up, but answered badly, or the connection itself failed. 504 Gateway Timeout means the upstream never answered in time at all — it might still be working, just too slowly. 503 Service Unavailable is different in kind: it is the server itself saying it is temporarily overloaded or down for maintenance, not a proxy reporting on something behind it.

    When debugging a 502 or 504 in a load-balanced or reverse-proxied setup, the actual problem is almost always in the application server the proxy is talking to, not the proxy itself — start there.

    Redirects: 301 versus 307, and why 302 got messy#

    301 Moved Permanently tells search engines to transfer ranking signals to the new URL and tells well-behaved clients to update their bookmarks. 302 Found was meant to be a simple temporary redirect, but its original specification was ambiguous enough that different browsers handled a POST-then-redirect differently for years.

    307 Temporary Redirect and 308 Permanent Redirect exist specifically to remove that ambiguity: they explicitly guarantee the original HTTP method and body are preserved on the follow-up request, which 302 and 301 never formally promised.

    Frequently asked questions

    What is the difference between 401 and 403?

    401 Unauthorized means the server does not know who you are — authentication is missing or failed. 403 Forbidden means the server does know who you are, and you are not allowed to access that resource regardless. 401 is about identity; 403 is about permission.

    What does a 502 Bad Gateway error mean?

    A proxy or load balancer in front of your application received an invalid or garbled response from the server behind it. The problem is almost always in that upstream application server, not in the proxy reporting the error.

    What is the difference between 502, 503 and 504?

    502 means a proxy got a bad response from its upstream server. 504 means the proxy got no response in time — a timeout, not necessarily a crash. 503 is different: it is the server itself reporting that it is temporarily overloaded or down, not a proxy relaying a problem from behind it.

    Should I use 301 or 302 for a redirect?

    301 for a permanent move — it tells search engines to transfer ranking signals to the new URL. 302 for a genuinely temporary redirect where the original URL should stay canonical. If the exact HTTP method needs to be preserved on the redirect, 308 and 307 are the modern, unambiguous equivalents of 301 and 302 respectively.

    Why did I get a 429 error?

    429 Too Many Requests means you have exceeded a rate limit. The response often includes a Retry-After header telling you how long to wait before trying again.

    What is a 499 status code?

    It is non-standard — not part of the official HTTP specification — but widely used by Nginx to log that the client closed the connection before the server finished responding. You will see it in server logs, not as something a browser displays.

    Developers

    UUID Generator

    Generate cryptographically random UUID v4 or time-ordered UUID v7, in bulk.

    Developers

    Base64 Encoder & Decoder

    Encode and decode Base64 with correct UTF-8 handling, including the URL-safe alphabet.

    Developers

    ULID Generator

    Generate ULIDs — sortable by creation time like UUID v7, but Crockford Base32 instead of hex.