Skip to main content
WizTools123
WizTools123
Free Online Tools

Tool Categories


Developer Tools New Tool

Free Online HTTP Status Code Lookup, Every Code Explained

Search every real HTTP status code by number or by the words in its meaning. Each code says what it actually means in practice, whether the response may carry a body, whether it is cacheable by default, and which RFC defines it, with the pairs people confuse most set side by side.

Free Forever Nothing Uploaded Grouped by class Nothing is fetched
Free Online HTTP Status Code Lookup, Every Code Explained
Share this tool
Advertisement Slot (Top Banner) Google AdSense Unit • Responsive Banner
HTTP Status Code Lookup Everything happens in this tab. Nothing you paste is sent anywhere.
The code you picked

-

Pick a code from the table below.

Body allowed-
Cacheable by default-
Defined in-

Summary
Search

0 of 0 codes

Code Reason phrase What it means Caches

No code matches that.

Buy Us A Coffee

Enjoying WizTools123? Help keep our server infrastructure 100% free and open for everyone.

Buy Us A Coffee
Sponsored Content (Below Tool) Google AdSense Placement

The Pairs That Get Mixed Up

Six decisions that are easy to get the wrong way round.

PairThe difference that matters
301 / 308 Both are permanent. A 301 lets the client change a POST into a GET, and almost every client does. A 308 requires the method and the body to be kept. Use 308 when the old URL might be posted to; use 301 for ordinary page moves.
302 / 307 Both are temporary, and the same method question applies: a 302 may be turned into a GET, a 307 may not. If you are redirecting after a form post and want the post repeated at the new place, 307 is the one. In practice 303 See Other is often what a post-then-redirect actually wants.
401 / 403 401 means the request was not authenticated, or the credentials were wrong, and it must carry a WWW-Authenticate header saying how to try again. 403 means the server knows who you are and the answer is still no. Logging in again cannot fix a 403.
404 / 410 404 says there is nothing here, and says nothing about the future. 410 says there was something here and it is gone deliberately. Search engines drop a 410 faster than a 404, so 410 is the honest code for content you have removed on purpose.
400 / 422 400 is for a request the server could not parse at all: broken JSON, a bad frame, a malformed header. 422 is for a request that parsed perfectly and then failed your rules, such as a valid JSON body with an email address that is not an email address.
502 / 503 / 504 502 means the upstream replied with something invalid. 503 means nothing is available to reply at all, and it is the one to pair with Retry-After during maintenance. 504 means the upstream was reached but took too long. Which one your proxy sends tells you where to look.

Two more worth knowing. 429 Too Many Requests should always carry Retry-After, otherwise the client has to guess and usually guesses wrong. 451 Unavailable For Legal Reasons exists so that a legal block can be told apart from an ordinary 403, and the number is a deliberate nod to Fahrenheit 451.

How to Look Up a Status Code

A few steps, and nothing is uploaded.

1
Type a number or a word Search runs on the code, the reason phrase and the explanation, so 404, gone and gateway all find something.
2
Or narrow by class Pick 3xx to see every redirect, or 5xx to see every server error. Turn on the last switch to hide the codes almost nobody sends.
3
Click a code The panel gives the reason phrase, what it means in practice, whether a body is allowed, whether it caches by default and the RFC that defines it.
4
Copy the summary The output box holds the code, the phrase and the facts as plain text, which is handy for a comment or a pull request.

What to Know About Status Codes

Including the redirect you cannot take back.

A 301 is cached by browsers, and sometimes kept for good. Browsers remember a permanent redirect and will not ask your server again, so if you send the wrong 301 the visitors who received it keep going to the wrong place even after you fix the server. There is no way to reach into their cache. Use 302 or 307 while you are still deciding, and 301 only when the move is genuinely permanent.
Cacheable by default is a short list, and it is not the obvious one. RFC 9110 makes only 200, 203, 204, 206, 300, 301, 308, 404, 405, 410, 414, 451 and 501 cacheable without any explicit header. Everything else caches only if Cache-Control or Expires says so. A 404 caching by default surprises people regularly.
This page explains codes; it does not check your server. There is no request made anywhere, so it cannot tell you what status your URL returns, follow a redirect chain or test a header. It is a reference. Use your browser's network tab or a command-line client for the live check.
A 204 and a 304 must not have a body, and a 1xx never does. Sending bytes after those headers breaks the framing of the connection, and some proxies will hang or truncate the next response rather than complain. The Body allowed column in the table is not a style preference; it is part of the protocol.

Key Features & Capabilities

What this tool does, and what it deliberately does not.

Every real code From 100 to 511, including the WebDAV and rarely used ones.
Search by meaning Words in the explanation match too, so "gone" finds 410.
The confusing pairs 301 and 308, 302 and 307, 401 and 403, 404 and 410, side by side.
Caching and bodies Whether each code caches by default and whether a body is allowed.
The defining RFC Each entry names the specification, so you can go and read it.
No requests made The whole table is in the page. Nothing is fetched and nothing is sent.

About the HTTP Status Code Lookup

A status code is the shortest message in HTTP and the one most often chosen carelessly. Anything that is not clearly a success tends to become a 400 or a 500, which makes logs harder to read and clients harder to write, because a well chosen code tells the other side whether to retry, whether to log in again, whether to fix the request or whether to give up.

This page lists every code that really exists, grouped by class, and for each one says what it means when you are actually building something rather than what the specification sentence says. The search runs across the number, the reason phrase and the explanation, so you can look for "gone" and find 410 without knowing the number.

The part worth the effort was the pairs. Almost nobody looks up 404 to find out what it means; they look up whether to use 301 or 308, or why their proxy sends 502 instead of 504. Those comparisons are in the panel next to the code itself, along with the caching behaviour, which is where the 301 trap lives.

Frequently Asked Questions

Redirects, caching, 401 against 403, and which gateway error is yours.

Use 308 if the old URL could ever receive a POST, because 308 requires the client to keep the method and the body, while 301 allows it to be turned into a GET and nearly every client does that. For ordinary page moves where only GET is involved, 301 is fine and is better understood by older clients and by search engines.

Because you sent a 301 and the browser cached it. A permanent redirect is remembered locally, sometimes for a very long time, so the browser never asks your server again. You cannot clear someone else's cache. While a move is uncertain, send 302 or 307, which are not cached by default.

403. A 401 means the request was not authenticated at all, or the credentials failed, and it must include a WWW-Authenticate header telling the client how to authenticate. If the user is known and simply not allowed, 403 is correct, because retrying with the same or better credentials will not help.

When the request was well formed and you understood it, but its contents broke your rules. Invalid JSON is a 400. Valid JSON with a missing required field, a date in the past or a duplicate email address is a 422. The distinction is useful to clients: a 400 usually means a bug in the request, a 422 usually means something to show the user.

That your proxy or load balancer reached the application behind it and got a reply it could not use, which normally means the application crashed, closed the connection or returned garbage. A 504 means the application was reached but never answered in time, and a 503 means the proxy had nothing to talk to at all. The three point at different places, so it is worth reading which one you got.

Other Developer Tools

Advertisement Slot (Bottom Banner) Google AdSense Unit • Responsive Banner