The Complete HTTP Status Codes Cheat Sheet for API Developers

Everything API developers need to know about HTTP status codes: 200, 201, 204, 400, 401, 403, 404, 422, 429, and 500 explained with practical scenarios.

HTTP status codes are standardized three-digit integers issued by a server in response to a client's request. Choosing the correct status code ensures that web browsers, API client libraries, and monitoring tools automatically know whether an operation succeeded, requires user action, or failed.

Core HTTP Status Categories

  • 2xx Success: The request was successfully received, understood, and accepted.
  • 3xx Redirection: Further action must be taken by the client to fulfill the request.
  • 4xx Client Errors: The client made a mistake (invalid syntax, missing credentials, bad permissions).
  • 5xx Server Errors: The server failed to fulfill an apparently valid request.

Most Critical Codes for REST APIs

200 OK: Standard response for successful GET, PUT, or PATCH. Success
201 Created: The resource was successfully created (returns Location header). Created
401 Unauthorized: Authentication credentials are missing or invalid. Client Error
403 Forbidden: Client is authenticated, but lacks permissions for this action. Forbidden
429 Too Many Requests: Rate limit exceeded. Read Retry-After header. Throttled
500 Internal Server Error: An unexpected exception occurred on the backend. Server Fault