HTTP Status Codes
Look up any HTTP status code
Search every standard HTTP status code with a plain-language explanation of what it means and when to use it.
- HTTP
- 404
- 500
- REST
How to use HTTP Status Codes
- Type in Search: a code (
404), the start of one (4or42), a class (5xx), a name (teapot) or any words from the explanation or a header name (rate limit,Retry-After). - Narrow the list with the Class buttons: All, 1xx, 2xx, 3xx, 4xx or 5xx.
- Read each card: what the code means, when to use it, whether it is cacheable by default, whether a retry can help, related headers and the RFC that defines it.
- Click a code to link straight to it: an address ending in
#404scrolls to and highlights that card.
How it works
The list is built into the page: 63 codes, covering the IANA HTTP Status Code Registry plus 418 I’m a teapot, each with the RFC section that defines it (mostly RFC 9110, HTTP Semantics). Obsolete codes such as 305 Use Proxy and 306 are marked Deprecated.
Search runs as you type. A one- to three-digit number matches codes starting with it, 4xx matches a whole class, and other text matches when every word appears in the code’s name, meaning, usage notes or headers. Exact and name matches are listed first.
“Cacheable by default” follows RFC 9110 and RFC 9111: caches may store these responses without explicit freshness headers. The retry hint says whether repeating the same request can succeed (yes, no or depends).
Limits
- Only registered codes (and 418) are listed. Vendor-specific codes such as nginx’s 499 or Cloudflare’s 52x aren’t included.
- Search is English-only and matches whole words or word fragments; it doesn’t correct typos.
- The retry and caching hints are general guidance; a specific server or API can behave differently.
Privacy
Everything is built into the page and searched in your browser; nothing is sent or stored. Copy share link puts your search, class filter and highlighted code in the link after the #, which browsers don’t send to servers.
Frequently asked questions
What is the difference between 401 and 403?
401 Unauthorized means the request has no valid credentials, so signing in may help; it comes with WWW-Authenticate. 403 Forbidden means the server knows who you are (or doesn’t care) and still refuses.
Should I use 301 or 308 for a permanent redirect?
Both mean “moved permanently”. With 301, clients may change a POST into a GET at the new URL; 308 requires them to repeat the same method and body. Use 308 for APIs and form endpoints, 301 is fine for page moves.
What does “Cacheable by default” mean?
Caches may store the response and reuse it even when it has no Cache-Control or Expires header, using a heuristic lifetime. Examples are 200, 301, 404 and 410. Other codes are only cached when headers allow it.
How do I link to a specific status code?
Add the code after a # in the address, for example /tools/http-status#429, or click the code on its card. The page scrolls to it and highlights it.
Is 418 I’m a teapot a real status code?
It comes from an April Fools’ RFC (the Hyper Text Coffee Pot Control Protocol) and is reserved (unused) in the IANA registry, so it has no standard meaning. Some servers still return it for requests they want to reject.
More tools
- Clean Image: Inspect and remove hidden image metadata
- JWT Decoder: Decode and verify JSON Web Tokens
- Diff Checker: Compare two texts line by line
- JS Runner: Run JavaScript and TypeScript in your browser
- JSON Formatter: Format, validate and minify JSON
- Encode / Decode: Base64, URL, HTML entity and hex
- Hash Generator: MD5, SHA and HMAC of any text
- UUID Generator: Generate UUID v4 and v7 in bulk
- Timestamp Converter: Unix time ↔ human dates
- Regex Tester: Test regular expressions live
- URL Parser: Break a URL into its parts
- MIME Type Lookup: File extension ↔ MIME type
- Password Generator: Strong random passwords and passphrases
- Random String Generator: Random tokens, IDs and keys
- Slug Generator: Turn titles into URL slugs
- Case Converter: camelCase, snake_case, Title Case and more
- Word Counter: Count words, characters and reading time
- JSON to TypeScript: Generate TypeScript types from JSON
- JSON Diff: Compare two JSON documents structurally
- JSON to SQL: Turn JSON arrays into SQL inserts
- YAML ↔ JSON: Convert between YAML and JSON
- XML ↔ JSON: Convert between XML and JSON
- CSV ↔ JSON: Convert between CSV and JSON
- CSV Viewer: View, sort and filter CSV files
- SQL Formatter: Format and beautify SQL queries
- cURL ↔ Fetch: Convert cURL commands to fetch and back
- Markdown Editor: Write Markdown with a live preview
- Text Cleaner: Remove duplicate lines, empty lines and extra spaces
- Find & Replace: Find and replace in any text
- Cron Expression Builder: Build and explain cron schedules
- User-Agent Parser: Identify browser, OS and device from a user agent
- HTTP Headers Inspector: Paste response headers and get them explained
- JWT Generator: Create and sign test JSON Web Tokens
- Certificate Inspector: Decode PEM certificates and keys
- Meta Tag Inspector: Check a page's SEO and social tags
- UTM Builder: Build campaign URLs with UTM parameters
- URL Cleaner: Strip tracking parameters from links
- Robots.txt Generator: Create and test a robots.txt file
- Sitemap Generator: Create an XML sitemap from a list of URLs
- Image Compressor: Shrink JPEG, WebP and AVIF images in your browser
- Image Resizer: Resize images by pixels, percentage or to fit a box
- Image Converter: Convert between PNG, JPEG, WebP and AVIF
- Image to Base64: Encode images as Base64 data URIs and decode them back
- SVG Optimizer: Minify and sanitize SVG files
- Favicon Generator: Make favicon.ico, Apple and Android icons from an image or emoji
- Color Converter: HEX, RGB, HSL, OKLCH and contrast checks
- Number Base Converter: Binary, octal, decimal, hex and float bits
- IP / CIDR Calculator: Subnets, masks and IP ranges for IPv4 and IPv6
- JSONPath Query: Query JSON with JSONPath expressions
- JSON Schema Validator: Validate JSON against a schema, or generate one
- Semver Checker: Check versions against semver ranges
- chmod Calculator: Unix permissions: rwx ↔ octal
- .env Diff: Compare and validate .env files
- TOTP Generator: Generate and verify 2FA codes
- String Escaper: Escape and unescape strings for any language
- Unicode Inspector: See every character, code point and hidden symbol
- Mock Data Generator: Generate realistic fake data
- QR Code Generator: Create QR codes for links, Wi-Fi and contacts
- Lorem Ipsum Generator: Placeholder text in paragraphs, sentences or words
- Date Calculator: Date differences, business days and durations
- Unit Converter: Convert bytes, lengths, weights, temperatures and more
- Query CSV with SQL: Run SQL queries on CSV files
- PDF Merge & Split: Merge, split, reorder and rotate PDFs
- PDF Metadata Cleaner: See and remove hidden PDF metadata
- Office Metadata Cleaner: Remove author and revision data from Word, Excel and PowerPoint
- Images to PDF: Combine images into one PDF
- Image Editor: Crop, rotate, resize and adjust images
- Encrypt / Decrypt Text: Encrypt text with a passphrase (AES-GCM)
- SSH Key Generator: Generate Ed25519 and RSA SSH keys locally
- Email Header Analyzer: Trace an email's path and check SPF, DKIM and DMARC
- JSON to Code: Generate Go, Python, Rust, Java, C# and Kotlin models from JSON
- docker run ↔ Compose: Convert docker run commands to docker-compose and back
- Color Palette Extractor: Pull the dominant colours out of any image
- Password Strength Checker: How long would your password take to crack?
- SPF / DKIM / DMARC Checker: Validate and explain email DNS records
- Kubernetes YAML Checker: Validate and explain Kubernetes manifests
- .gitignore Generator: Build a .gitignore from presets
- CSP Builder: Build and check a Content-Security-Policy
- JSON-LD Generator: Create schema.org structured data
- Open Graph Image Generator: Make 1200×630 social preview images
- CSS Generator: Gradients, shadows, clamp() and more
- Time Zone Meeting Planner: Find meeting times across time zones