Screenshot-worthyBeginner guides·6 min read

HTTP Status Codes, Explained by an Intern (With Memes)

You will send this to a friend.

I had to learn these the hard way. Here is the version I wish I had: what each code means, one joke each, and what your UI should do about it.

If you read nothing else

  • 2xx worked, 3xx go elsewhere, 4xx your request was wrong, 5xx the server was wrong.
  • 401 means "who are you", 403 means "I know who you are, and no".
  • You can fake any of these in the browser to see how your UI behaves.

The five families in one glance

RangeMeaningVibe
1xxInformationalHold on, working on it
2xxSuccessNailed it
3xxRedirectNot here, go there
4xxClient errorYou did something wrong
5xxServer errorWe did something wrong
4xx: your fault
5xx: their fault
Blame allocation, simplified.

The greatest hits

CodeNameWhat the UI should do
200OKRender the data
301 / 302MovedFollow the redirect (the browser usually does)
400Bad RequestShow which field was wrong
401UnauthorizedSend the user to sign in
403ForbiddenExplain that they lack permission
404Not FoundShow a helpful empty or not-found page
418I am a teapotA joke code from a 1998 April Fools RFC
429Too Many RequestsBack off, then retry later
500Internal Server ErrorApologise, offer retry
502 / 503 / 504Bad gateway, unavailable, timeoutRetry with backoff, show status

Try them yourself, safely

You do not need a broken server to see a 429. Add an interceptor rule for an endpoint, set the status to 429, and reload. Your app gets exactly what it would get in production, and your real backend is untouched.

Me: handles 200
Also me: 429 exists?
Learned this one in week one.
Please be gentle. I am the intern. I will now go test 401 vs 403 properly.

Frequently asked questions

What is the difference between 401 and 403?

401 means the request is not authenticated (no or bad credentials). 403 means the user is authenticated but not allowed to do that.

Written by

Arnav Khond Intern

Arnav is the intern, and the voice for anyone meeting API debugging for the first time. He writes what he wishes someone had explained on day one: plain language, small steps and the occasional meme when a status code deserves one. Expect honest questions, no gatekeeping and a lot of learning in public.

“Please be gentle. I am the intern.”

More from Arnav →

Read next

Intercept your first request in under a minute

Create a free ProxyCeptor account to mock, delay, block and rewrite API traffic, then share the same rules with your team.

🚀 Mock, delay and break API calls in ChromeTry ProxyCeptor free