- 400Bad RequestRFC 9110
- The server can't process the request because it's malformed.
- Invalid JSON, missing required fields or invalid parameters. The response body should explain what's wrong.
- 401UnauthorizedRFC 9110
- Authentication is required or has failed.
- Despite the name, it means unauthenticated. The client should log in or send valid credentials. Includes a WWW-Authenticate header.
- 402Payment RequiredRFC 9110
- Reserved for future use; some APIs use it for billing problems.
- 403ForbiddenRFC 9110
- The server understood the request but refuses to authorise it.
- The client is known but lacks permission. Logging in again won't help.
- 404Not FoundRFC 9110
- The server can't find the requested resource.
- Also used to hide the existence of a resource from unauthorised users.
- 405Method Not AllowedRFC 9110
- The method isn't supported for this resource, e.g. DELETE on a read-only endpoint.
- Must include an Allow header listing supported methods.
- 406Not AcceptableRFC 9110
- The server can't produce a response matching the Accept headers.
- 407Proxy Authentication RequiredRFC 9110
- The client must authenticate with a proxy.
- 408Request TimeoutRFC 9110
- The server timed out waiting for the request.
- 409ConflictRFC 9110
- The request conflicts with the current state of the resource.
- Examples: editing a stale version, or creating a user whose email already exists.
- 410GoneRFC 9110
- The resource was deliberately removed and won't come back.
- Tells search engines to drop the URL faster than a 404.
- 411Length RequiredRFC 9110
- The request needs a Content-Length header.
- 412Precondition FailedRFC 9110
- A condition in the request headers (such as If-Match) wasn't met.
- Used for optimistic concurrency control.
- 413Content Too LargeRFC 9110
- The request body is larger than the server allows.
- Formerly called “Payload Too Large”. Seen when uploading files above a limit.
- 414URI Too LongRFC 9110
- The URL is longer than the server will process.
- 415Unsupported Media TypeRFC 9110
- The request body's format isn't supported.
- Often a missing or wrong Content-Type header, e.g. sending form data to a JSON endpoint.
- 416Range Not SatisfiableRFC 9110
- The requested byte range is outside the resource.
- 417Expectation FailedRFC 9110
- The server can't meet the Expect request header.
- 418I'm a teapotRFC 2324 (non-standard)
- An April Fools' joke from the Hyper Text Coffee Pot Control Protocol.
- Not part of HTTP proper, but reserved so it won't be reused, and some sites use it playfully.
- 421Misdirected RequestRFC 9110
- The request was sent to a server that can't respond for this host.
- 422Unprocessable ContentRFC 9110
- The request is well-formed but contains invalid data.
- Widely used by APIs for validation errors, e.g. a malformed email address.
- 423LockedRFC 4918
- The resource is locked (WebDAV).
- 425Too EarlyRFC 8470
- The server won't risk processing a request that might be replayed.
- 426Upgrade RequiredRFC 9110
- The client must switch to a different protocol.
- 428Precondition RequiredRFC 6585
- The server requires conditional requests to prevent lost updates.
- 429Too Many RequestsRFC 6585
- The client has sent too many requests in a given time (rate limiting).
- Check the Retry-After header and back off before retrying.
- 431Request Header Fields Too LargeRFC 6585
- The headers are too large — often because of oversized cookies.
- 451Unavailable For Legal ReasonsRFC 7725
- Access is blocked for legal reasons, such as a court order.