Free Online HTTP Status Code Lookup, Every Code Explained
Search every real HTTP status code by number or by the words in its meaning. Each code says what it actually means in practice, whether the response may carry a body, whether it is cacheable by default, and which RFC defines it, with the pairs people confuse most set side by side.
-
Pick a code from the table below.
| Body allowed | - |
|---|---|
| Cacheable by default | - |
| Defined in | - |
Enjoying WizTools123? Help keep our server infrastructure 100% free and open for everyone.
The Pairs That Get Mixed Up
Six decisions that are easy to get the wrong way round.
| Pair | The difference that matters |
|---|---|
| 301 / 308 | Both are permanent. A 301 lets the client change a POST into a GET, and almost every client does. A 308 requires the method and the body to be kept. Use 308 when the old URL might be posted to; use 301 for ordinary page moves. |
| 302 / 307 | Both are temporary, and the same method question applies: a 302 may be turned into a GET, a 307 may not. If you are redirecting after a form post and want the post repeated at the new place, 307 is the one. In practice 303 See Other is often what a post-then-redirect actually wants. |
| 401 / 403 | 401 means the request was not authenticated, or the credentials were wrong, and it must carry a WWW-Authenticate header saying how to try again. 403 means the server knows who you are and the answer is still no. Logging in again cannot fix a 403. |
| 404 / 410 | 404 says there is nothing here, and says nothing about the future. 410 says there was something here and it is gone deliberately. Search engines drop a 410 faster than a 404, so 410 is the honest code for content you have removed on purpose. |
| 400 / 422 | 400 is for a request the server could not parse at all: broken JSON, a bad frame, a malformed header. 422 is for a request that parsed perfectly and then failed your rules, such as a valid JSON body with an email address that is not an email address. |
| 502 / 503 / 504 | 502 means the upstream replied with something invalid. 503 means nothing is available to reply at all, and it is the one to pair with Retry-After during maintenance. 504 means the upstream was reached but took too long. Which one your proxy sends tells you where to look. |
Two more worth knowing. 429 Too Many Requests should always carry
Retry-After, otherwise the client has to guess and usually guesses wrong.
451 Unavailable For Legal Reasons exists so that a legal block can be told apart
from an ordinary 403, and the number is a deliberate nod to Fahrenheit 451.
How to Look Up a Status Code
A few steps, and nothing is uploaded.
What to Know About Status Codes
Including the redirect you cannot take back.
Cache-Control or Expires says so. A 404 caching by default surprises people regularly.
Key Features & Capabilities
What this tool does, and what it deliberately does not.
About the HTTP Status Code Lookup
A status code is the shortest message in HTTP and the one most often chosen carelessly. Anything that is not clearly a success tends to become a 400 or a 500, which makes logs harder to read and clients harder to write, because a well chosen code tells the other side whether to retry, whether to log in again, whether to fix the request or whether to give up.
This page lists every code that really exists, grouped by class, and for each one says what it means when you are actually building something rather than what the specification sentence says. The search runs across the number, the reason phrase and the explanation, so you can look for "gone" and find 410 without knowing the number.
The part worth the effort was the pairs. Almost nobody looks up 404 to find out what it means; they look up whether to use 301 or 308, or why their proxy sends 502 instead of 504. Those comparisons are in the panel next to the code itself, along with the caching behaviour, which is where the 301 trap lives.
Frequently Asked Questions
Redirects, caching, 401 against 403, and which gateway error is yours.