I had to learn these the hard way. Here is the version I wish I had: what each code means, one joke each, and what your UI should do about it.
If you read nothing else
2xx worked, 3xx go elsewhere, 4xx your request was wrong, 5xx the server was wrong.
401 means "who are you", 403 means "I know who you are, and no".
You can fake any of these in the browser to see how your UI behaves.
The five families in one glance
Range
Meaning
Vibe
1xx
Informational
Hold on, working on it
2xx
Success
Nailed it
3xx
Redirect
Not here, go there
4xx
Client error
You did something wrong
5xx
Server error
We did something wrong
4xx: your fault
🫠
5xx: their fault
Blame allocation, simplified.
The greatest hits
Code
Name
What the UI should do
200
OK
Render the data
301 / 302
Moved
Follow the redirect (the browser usually does)
400
Bad Request
Show which field was wrong
401
Unauthorized
Send the user to sign in
403
Forbidden
Explain that they lack permission
404
Not Found
Show a helpful empty or not-found page
418
I am a teapot
A joke code from a 1998 April Fools RFC
429
Too Many Requests
Back off, then retry later
500
Internal Server Error
Apologise, offer retry
502 / 503 / 504
Bad gateway, unavailable, timeout
Retry with backoff, show status
Try them yourself, safely
You do not need a broken server to see a 429. Add an interceptor rule for an endpoint, set the status to 429, and reload. Your app gets exactly what it would get in production, and your real backend is untouched.
Me: handles 200
😳
Also me: 429 exists?
Learned this one in week one.
Please be gentle. I am the intern. I will now go test 401 vs 403 properly.
Frequently asked questions
What is the difference between 401 and 403?
401 means the request is not authenticated (no or bad credentials). 403 means the user is authenticated but not allowed to do that.
Arnav is the intern, and the voice for anyone meeting API debugging for the first time. He writes what he wishes someone had explained on day one: plain language, small steps and the occasional meme when a status code deserves one. Expect honest questions, no gatekeeping and a lot of learning in public.
Five short exercises that take you from "what is a proxy interceptor?" to mocking, deep-merging, failing and redirecting real API calls, with copy-paste rules.