The five classes, in one sentence each#
1xx (Informational) — the request is still being processed; rare to see directly, since browsers handle these automatically. 2xx (Success) — the request worked. 3xx (Redirection) — more steps are needed to complete the request, usually because the resource moved. 4xx (Client error) — something about the request itself was wrong. 5xx (Server error) — the request was probably fine; the server failed to handle it.
The class alone tells you where to start looking: a 4xx means check what you sent, a 5xx means check what the server did with it.
401 versus 403: authentication versus authorization#
This is the pair that gets swapped most often. 401 Unauthorized genuinely means "unauthenticated" — the server does not know who you are yet, and per spec must include a WWW-Authenticate header explaining how to log in. 403 Forbidden means the server does know who you are, and the answer is still no.
A login page correctly returns 401 to an unauthenticated visitor. An authenticated user trying to access someone else's private data should get 403, not 401 — they are logged in; they are just not allowed to see that particular thing.
502, 503 and 504: who actually failed#
All three sound like "the server is broken," but they point at different things. 502 Bad Gateway means a proxy or load balancer got a garbled or invalid response from the application server behind it — the upstream is up, but answered badly, or the connection itself failed. 504 Gateway Timeout means the upstream never answered in time at all — it might still be working, just too slowly. 503 Service Unavailable is different in kind: it is the server itself saying it is temporarily overloaded or down for maintenance, not a proxy reporting on something behind it.
When debugging a 502 or 504 in a load-balanced or reverse-proxied setup, the actual problem is almost always in the application server the proxy is talking to, not the proxy itself — start there.
Redirects: 301 versus 307, and why 302 got messy#
301 Moved Permanently tells search engines to transfer ranking signals to the new URL and tells well-behaved clients to update their bookmarks. 302 Found was meant to be a simple temporary redirect, but its original specification was ambiguous enough that different browsers handled a POST-then-redirect differently for years.
307 Temporary Redirect and 308 Permanent Redirect exist specifically to remove that ambiguity: they explicitly guarantee the original HTTP method and body are preserved on the follow-up request, which 302 and 301 never formally promised.