Developer & Data UtilitiesUpdated: September 2026

HTTP Status Codes Reference & RFC 9110 Directory

Searchable technical directory of HTTP response status codes (1xx, 2xx, 3xx, 4xx, 5xx) conforming to RFC 9110. Root causes, cacheability, and developer troubleshooting guides.

Research: LocalTooldeck Financial & Engineering Team
Audit: Verified for Mathematical Accuracy
Advertisement
Reserved 728×90 Top Responsive LeaderboardCLS Guard: Strict Layout Reservation (min-height: 250px)

100% Secure & Client-Side: Complete offline RFC 9110 specification database. Zero tracking or telemetry.

Showing 63 HTTP specificationsClick any card to inspect troubleshooting details

The Semantic Architecture of HTTP Response Codes Under RFC 9110

In distributed computer networking, HyperText Transfer Protocol (HTTP) serves as the primary stateless application-layer communication protocol for the Internet. When an HTTP client issues a request to an origin server or intermediary proxy, the responder returns a numeric three-digit status code accompanied by a short textual reason phrase.

First codified under RFC 1945 (HTTP/1.0) and later expanded in RFC 2616 and RFC 7231, the canonical standard was consolidated in June 2022 under RFC 9110 ("HTTP Semantics") by the Internet Engineering Task Force (IETF). RFC 9110 defines status codes as three-digit integers where the initial digit establishes the semantic category of the response:

1xx

Informational

Request received, continuing process.

2xx

Success

Action successfully understood and accepted.

3xx

Redirection

Further action required to complete request.

4xx

Client Error

Invalid syntax or unauthorized request.

5xx

Server Error

Server failed to fulfill an apparently valid request.

Critical Status Code Distinctions in Microservice Architectures

In distributed cloud environments involving reverse proxies (Envoy, Nginx, Cloudflare) and downstream Kubernetes pods, software engineers must distinguish between subtly differing failure codes:

1. 401 Unauthorized vs 403 Forbidden

A 401 Unauthorized explicitly indicates that authentication is missing or invalid. The response must include a WWW-Authenticate challenge header informing the client how to supply credentials. Conversely, a 403 Forbidden indicates that the server knows who the client is, but that authenticated user lacks the authorization permissions required to access the requested resource. Re-authenticating will not alter the outcome.

2. 502 Bad Gateway vs 503 Service Unavailable vs 504 Gateway Timeout

These three errors represent the most frequent production outage indicators:

  • 502 Bad Gateway: The edge proxy successfully reached the upstream application server, but the upstream process crashed, closed the socket abruptly, or emitted an invalid HTTP framing header.
  • 503 Service Unavailable: The server or upstream pool is temporarily unable to handle requests due to planned maintenance or severe CPU/connection pool saturation. It frequently includes a Retry-After header.
  • 504 Gateway Timeout: The edge proxy established a connection to the upstream server, but the backend query took longer to process than the proxy's configured proxy_read_timeout (e.g. 60 seconds).

Core Status Code Reference Matrix

Code & PhraseRFC StandardDefault CacheablePrimary Meaning
200 OKRFC 9110 §15.3.1YesStandard successful HTTP transaction payload returned.
201 CreatedRFC 9110 §15.3.2NoNew resource created; Location header indicates URI.
301 Moved PermanentlyRFC 9110 §15.4.2YesTarget resource assigned a new permanent URI.
304 Not ModifiedRFC 9110 §15.4.5YesCached copy is fresh; client loads from local storage.
400 Bad RequestRFC 9110 §15.5.1NoMalformed syntax, invalid JSON, or missing required attributes.
429 Too Many RequestsRFC 6585 §4NoRate limit quota exceeded; client must throttle via Retry-After.
500 Internal ErrorRFC 9110 §15.6.1NoUnhandled server-side exception or database fatal crash.

Best Practices for API Error Handling and Idempotency

When architecting RESTful services, engineering teams must maintain precise adherence to status code semantics:

  • Never Return 200 OK with Embedded Errors: Anti-patterns where endpoints respond with 200 OK containing {"success": false, "error": "User not found"} break HTTP monitoring, CDN caching layers, and client-side retry mechanisms. Always emit appropriate 4xx or 5xx codes.
  • Enforce Idempotency on 409 Conflict: When concurrent requests attempt to modify the same resource simultaneously (such as double booking an inventory item), return 409 Conflict with version headers (ETags) to allow optimistic concurrency control.
Advertisement
Reserved 336×280 In-Content RectangleCLS Guard: Strict Layout Reservation (min-height: 280px)

Frequently Asked Questions (US Standards)

What is the authoritative standard governing HTTP status codes?
In June 2022, the Internet Engineering Task Force (IETF) published RFC 9110 ("HTTP Semantics"), formally obsoleting RFC 7231 and consolidating the canonical registry of HTTP status codes, method semantics, and core message headers across HTTP/1.1, HTTP/2, and HTTP/3.
What is the difference between 502 Bad Gateway and 504 Gateway Timeout?
Both errors occur at reverse proxies or API gateways (such as Nginx, Cloudflare, or AWS ALB). A 502 Bad Gateway means the proxy contacted the upstream origin server, but the origin returned an invalid or unparseable HTTP response (or closed the TCP socket prematurely). A 504 Gateway Timeout means the proxy waited for the upstream origin to respond, but the request exceeded the proxy read timeout threshold before receiving any bytes.
How should API developers properly implement 429 Too Many Requests?
Under RFC 6585, a server returning HTTP 429 should include a Retry-After header indicating either the number of seconds the client must wait (e.g. Retry-After: 60) or a specific UTC HTTP-date timestamp before making subsequent requests. Pair this with RateLimit-Limit and RateLimit-Remaining headers to allow clients to throttle dynamically.
Which HTTP status codes are cacheable by default?
Under RFC 9110 Section 15, responses with status codes 200 (OK), 203 (Non-Authoritative Information), 204 (No Content), 206 (Partial Content), 300 (Multiple Choices), 301 (Moved Permanently), 404 (Not Found), 405 (Method Not Allowed), 410 (Gone), 414 (URI Too Long), and 501 (Not Implemented) can be cached by intermediate proxies and web browsers unless explicitly forbidden by Cache-Control response headers.
Advertisement
Reserved Responsive Bottom PlacementCLS Guard: Strict Layout Reservation (min-height: 250px)
Advertisement
Reserved 320×100 Mobile Anchor