HTTP Status Code
- In Turkish
- HTTP Durum Kodu
In short
An HTTP status code is a three-digit number a server sends with every response to tell the client whether the request succeeded, failed, or needs more action.
What is an HTTP status code?
Every HTTP response begins with a status code, a three-digit number that summarizes what happened to the request. A browser, app, or script reads this number to decide what to do next, such as showing the page, following a redirect, or displaying an error. The code comes with a short reason phrase, like 404 Not Found, that describes it for humans.
The first digit puts each code into one of five classes: 1xx informational, 2xx success, 3xx redirection, 4xx client error, and 5xx server error. Common examples include 200 OK, 201 Created, 301 Moved Permanently, 304 Not Modified, 400 Bad Request, 404 Not Found, 429 Too Many Requests, 500 Internal Server Error, and 503 Service Unavailable. The codes are defined in the HTTP specification, RFC 9110, so every client and server interprets them the same way.
Status codes work like the short notes a delivery service leaves: delivered, moved to a new address, wrong address, or depot closed. The most useful distinction is between the last two classes: a 4xx code means the client sent something wrong and should change the request, while a 5xx code means the server failed even though the request may have been fine.
Two codes that are often confused are 401 Unauthorized and 403 Forbidden. Despite its name, 401 means the client is not authenticated, for example because a login token is missing or expired, while 403 means the server knows who the client is but won't allow the action. Another common mistake is returning 200 OK with an error message in the body, which hides failures from clients, monitoring tools, and caches.
Key takeaways
- Every HTTP response includes a three-digit status code.
- The first digit gives the class:
1xxinfo,2xxsuccess,3xxredirect,4xxclient error,5xxserver error. - A
4xxerror means the request should change; a5xxerror means the server failed. 401means not authenticated, while403means authenticated but not allowed.- APIs should return accurate codes instead of
200 OKfor every response.
Example
// Check the status code before using the response
const response = await fetch("https://api.example.com/users/42");
if (response.ok) { // true for any 2xx status
const user = await response.json();
console.log(user.name);
} else if (response.status === 404) {
console.log("User not found");
} else if (response.status >= 500) {
console.log("Server error, try again later");
} else {
console.log(`Request failed with status ${response.status}`);
}Readers ask
What is the difference between 401 and 403?
401 Unauthorized means the request lacks valid authentication, so the client should log in or send a valid token. 403 Forbidden means the server knows who the client is, but that user is not allowed to perform the action.
What is the difference between a 301 and a 302 redirect?
301 Moved Permanently tells browsers and search engines that the resource has moved for good, so they should use the new URL from now on. 302 Found is a temporary redirect, so clients should keep using the original URL in the future.
What does a 500 error mean?
500 Internal Server Error is a generic code meaning something went wrong on the server, such as an unhandled exception in its code. The problem is on the server side, so the fix usually has to be made there, not by the user.
See also
- HTTPWeb Development, p. 19HTTP is the protocol that browsers, apps, and servers use to exchange web pages and data through a simple cycle of requests and responses.
- REST APIBackend & APIs, p. 38A REST API is a web API that exposes data as resources identified by URLs and lets clients read or change them using standard HTTP methods.
- APIBackend & APIs, p. 2An API is a set of rules that lets one piece of software request data or actions from another in a predictable, documented way.
- Web BrowserWeb Development, p. 57A web browser is an application that fetches web pages from servers and turns their HTML, CSS, and JavaScript into the interactive pages you see on screen.
- Rate LimitingBackend & APIs, p. 37Rate limiting is a technique that caps how many requests a client can make to a server or API within a time window, protecting it from abuse and overload.
- SEOWeb Development, p. 39SEO is the practice of improving a website's content and technical setup so that search engines can find, understand, and rank its pages for relevant searches.
Spotted a mistake or something missing on this page?Suggest an edit