The request headers are fine; send the body.
Almost never set by hand. A client sends Expect: 100-continue before a large body so it can be rejected before uploading.
The connection is changing protocol, usually to WebSocket.
Emitted by the server during a WebSocket handshake. Not something an application returns.
Preliminary headers while the real response is prepared.
To send Link headers so the browser can preload assets before the page itself is ready.
The request succeeded and the body carries the result.
The default for a successful GET, or a PUT or POST that returns content.
The request succeeded and a new resource now exists.
A POST or PUT that created something. Send a Location header pointing at it — that is the part usually forgotten.
Madalas mapagkamalan sa 200 OK · 202 Accepted
The request was accepted but has not been carried out yet.
Queued work. Use it when you cannot promise the result, and give the caller somewhere to check progress.
Madalas mapagkamalan sa 201 Created · 200 OK
Succeeded, and there is deliberately no body.
A DELETE that worked, or a PUT with nothing to return. A 204 with a body is a contradiction and some clients will drop it.
Madalas mapagkamalan sa 200 OK · 205 Reset Content
Succeeded, and the client should clear the form it sent.
Rare, and genuinely different from 204: 204 says "nothing to show", 205 says "nothing to show AND reset your input". Also carries no body.
Madalas mapagkamalan sa 204 No Content
Part of the resource, in response to a Range request.
Video seeking and resumable downloads. Must echo Content-Range.
The resource has a new URL, for good.
A permanent move. Crawlers transfer ranking signals to the new URL. **Cached aggressively and hard to undo** — be sure before sending one.
Madalas mapagkamalan sa 302 Found · 308 Permanent Redirect
The resource is temporarily elsewhere.
A temporary move. Historically it let clients change POST to GET, which is why 307 exists.
Madalas mapagkamalan sa 301 Moved Permanently · 307 Temporary Redirect
Look at this other URL, with a GET.
After a successful POST, to stop a refresh resubmitting the form. The POST-redirect-GET pattern.
Madalas mapagkamalan sa 302 Found · 307 Temporary Redirect
Your cached copy is still good.
In reply to a conditional request carrying If-None-Match or If-Modified-Since. Carries no body by design.
Temporarily elsewhere, and keep the method.
Like 302 but the method and body must be preserved — a POST stays a POST. Use it when that matters.
Madalas mapagkamalan sa 302 Found · 308 Permanent Redirect
Permanently elsewhere, and keep the method.
Like 301 but the method is preserved. The right choice for a permanently moved API endpoint.
Madalas mapagkamalan sa 301 Moved Permanently · 307 Temporary Redirect
The request is malformed and the server will not process it.
Syntax errors — unparseable JSON, a missing required field. Not for a request that is well-formed but refused.
Madalas mapagkamalan sa 422 Unprocessable Content · 404 Not Found
You are not authenticated. The name is wrong — it means unauthenticated.
No credentials, or bad ones. Signing in could fix it. Must carry a WWW-Authenticate header.
Madalas mapagkamalan sa 403 Forbidden
You are authenticated and still not allowed.
Signing in again will not help. **The distinction from 401 is the single most muddled pair in HTTP**: 401 is "who are you?", 403 is "I know who you are, and no".
Madalas mapagkamalan sa 401 Unauthorized · 404 Not Found
No resource at this URL.
Also the right answer when you do not wish to confirm a resource exists to someone with no right to it — better than 403 there, because a 403 confirms it.
Madalas mapagkamalan sa 403 Forbidden · 410 Gone
The URL exists; that verb does not apply to it.
A POST to a read-only endpoint. Must list the permitted verbs in an Allow header.
Madalas mapagkamalan sa 404 Not Found · 501 Not Implemented
The request clashes with the current state.
An edit against a version that has since moved, or a duplicate unique value. Say what conflicted.
Madalas mapagkamalan sa 422 Unprocessable Content · 412 Precondition Failed
It was here and has been deliberately removed.
Stronger than 404: it tells a crawler to drop the URL rather than keep retrying. Only when you know it is permanent.
Madalas mapagkamalan sa 404 Not Found
A condition you attached did not hold.
The other half of optimistic concurrency, with If-Match. Stops a blind overwrite.
Madalas mapagkamalan sa 409 Conflict · 428 Precondition Required
The body is bigger than the server will take.
Upload limits. Formerly "Payload Too Large".
The Content-Type is not one this endpoint accepts.
A form posted to a JSON-only endpoint. About the format, never about the values.
Madalas mapagkamalan sa 400 Bad Request · 422 Unprocessable Content
Well-formed, understood, and semantically wrong.
Validation failures — a date in the past where a future one is required. **This is the code most APIs should use where they send 400.**
Madalas mapagkamalan sa 400 Bad Request · 409 Conflict
The server insists the request be conditional.
Forces a client to send If-Match, so concurrent edits cannot silently overwrite each other.
You are being rate limited.
Send Retry-After. A 429 with no indication of when to try again leaves a client guessing or hammering.
Blocked for legal reasons.
Court orders and statutory blocks. The number is a Fahrenheit 451 reference and that is deliberate.
Something broke and the server cannot be more specific.
The catch-all for an unhandled exception. Never leak the stack trace to the caller.
Madalas mapagkamalan sa 502 Bad Gateway · 503 Service Unavailable
The server does not support the method at all.
For a verb the server does not implement anywhere. Not for one that merely does not apply here — that is 405.
Madalas mapagkamalan sa 405 Method Not Allowed
A proxy got an invalid response from upstream.
The upstream answered with rubbish, or died mid-response. Your application is probably the upstream.
Madalas mapagkamalan sa 503 Service Unavailable · 504 Gateway Timeout
Temporarily unable to handle the request.
Maintenance or overload. Send Retry-After. **Use this rather than 500 during a deploy** — it tells a crawler to come back rather than to drop the page.
Madalas mapagkamalan sa 500 Internal Server Error · 502 Bad Gateway
A proxy gave up waiting for upstream.
The upstream never answered. 502 means a bad answer; 504 means no answer at all.
Madalas mapagkamalan sa 502 Bad Gateway · 503 Service Unavailable
Hindi ang pangalan ang mahirap. Alam ng lahat na "Not Found" ang 404. Ang magkapares na madaling magkamali ang kumakain ng oras.
401 laban sa 403 ang pinakamalabo sa HTTP, at kasalanan ito ng pangalan: ang 401 ay nagsasabing "Unauthorized" pero ang ibig sabihin ay hindi pa nakikilala. Ang 401 ay "sino ka?"; ang 403 ay "kilala kita, at hindi puwede".
Ang 400 laban sa 422 ay isa pa. Ang 400 ay para sa hindi mabasang request; ang 422 ay para sa request na tama ang anyo at mali ang laman. Karamihan sa API ay nagpapadala ng 400 sa dalawa, at karamihan doon ay 422 talaga.
Kaya bawat entry dito ay may kailan gagamitin, hindi lang kahulugan — at pinapangalanan ang kapares na madaling mapagkamalan.
Ang 401 ay nangangahulugang hindi alam ng server kung sino ka — walang kredensiyal, o mali — at puwedeng maayos ito ng pag-sign in. Ang 403 ay nangangahulugang alam na alam niya kung sino ka at hindi ka pa rin puwede. Ang pangalan ng 401 ang problema: sinasabi nitong “Unauthorized” at ang ibig sabihin ay hindi napatunayan. Kailangan ding may dalang WWW-Authenticate header ang 401 na nagsasabi kung paano magpapatunay, at iyon ang bahaging madalas iwanan.
Kadalasan ay mas magandang sagot ang 404. Kinukumpirma ng 403 na umiiral ang resource, at sinasabi niyon sa taong walang karapatan dito na nakahanap siya ng tunay na URL — ganoon inililista ng umaatake kung ano ang sulit atakihin. Walang ibinibigay ang 404. Ganoon din ang ginagawa ng site na ito para sa naka-save na datos ng ibang miyembro.
Ang 400 ay para sa request na hindi mabasa ng server — sirang JSON, kulang na kailangang patlang, ganap na maling hugis. Ang 422 ay para sa request na maayos ang anyo at mali ang kahulugan, tulad ng petsang nakaraan kung saan kailangan ng hinaharap. Karamihan sa API ay nagpapadala ng 400 sa dalawa, at karamihan sa mga kasong iyon ay 422 talaga.
Dalawang tanong: permanente ba ito, at kailangan bang makaligtas ang method? Ang 301 ay permanente at sa kasaysayan ay pinapayagan ang kliyenteng gawing GET ang POST. Ang 308 ay permanente at pinapanatili ang method. Ang 302 ay pansamantala na may parehong kalabuan sa method; ang 307 ay pansamantala at pinapanatili ito. Para sa API endpoint na lumipat ay halos laging 308 ang gusto mo. Mag-ingat sa 301 — mabigat itong ina-cache at mahirap bawiin.
Parehong galing sa bagay na nakaupo sa harap ng aplikasyon mo. Ang 502 ay nangangahulugang sumagot ang upstream ng wala sa lugar, o namatay sa gitna ng pagsagot. Ang 504 ay nangangahulugang hindi kailanman sumagot ang upstream bago sumuko ang proxy. Kung inaayos mo ang sarili mong serbisyo sa likod ng proxy, ang 502 ay kadalasang tumuturo sa pagbagsak at ang 504 sa bagay na mabagal.
503 Service Unavailable, kasama ang Retry-After header. Sinasabi nito sa crawler na pansamantalang wala ang pahina at bumalik muli, samantalang ang 500 ay nagpapahiwatig na may sira at ang 404 ay nagpapahiwatig na wala na ang pahina. Ang maling pagbabalik sa loob ng ilang minuto ng pagmamantini ay puwedeng magpalabas ng pahina sa index.
Tunay itong nakarehistrong code mula sa espesipikasyong biro noong Abril 1998, at sinasadyang wala ito sa listahang ito. Walang silbi ito sa tunay na API, at ang pagsama nito katabi ng mga code na pinagpipilian ng mga tao ay nagdaragdag ng ingay sa isang sanggunian.
Ang 4xx at 5xx ang tunay na paghahati: sasabihin ng 4xx na baguhin ang request, at sasabihin ng 5xx na tama ang request at ang server ang may problema.
Magpadala ng 503 na may Retry-After. Sinasabi nito sa crawler na pansamantala lang at babalik ito. Ang 500 ay nagpapahiwatig ng sira; ang 404 ay nagpapahiwatig na wala na. Ang maling pagpili sa loob ng ilang minutong maintenance ay puwedeng magpatanggal ng pahina sa index.
A reference, not a specification. Every code cites the RFC it comes from — read that where the exact wording matters. Walang ipinapadala sa mga server namin ang tina-type mo rito — sa browser mo tumatakbo nang buo ang pagkuwenta.