- Bad Request
- The server couldn't understand the request — often malformed JSON or missing fields.
- Unauthorized
- You need to log in or send valid credentials.Tip: Despite the name, this means “unauthenticated”.
- Payment Required
- Reserved for payment flows; some APIs use it when a subscription or credit is needed.
- Forbidden
- The server knows who you are but you're not allowed to access this.
- Not Found
- Nothing exists at this address.Tip: Make sure removed pages return 404 (or 410), not a 200 page that says “not found”.
- Method Not Allowed
- The URL exists but doesn't accept this method (for example POST instead of GET).
- Not Acceptable
- The server can't produce a response in any format the client accepts.
- Request Timeout
- The client took too long to send the request.
- Conflict
- The request conflicts with the current state, such as editing an outdated version.
- Gone
- The resource was deliberately removed and won't come back.
- Length Required
- The server needs a Content-Length header.
- Precondition Failed
- A condition in the request headers (like If-Match) wasn't met.
- Content Too Large
- The request body (often an upload) is bigger than the server allows.
- URI Too Long
- The URL is longer than the server will process.
- Unsupported Media Type
- The server doesn't accept the body's format — check the Content-Type header.
- Range Not Satisfiable
- The requested byte range is outside the file.
- I'm a teapot
- An April Fools' joke from 1998 (RFC 2324). Some services use it playfully.
- Unprocessable Content
- The request is well-formed but the data fails validation.
- Too Early
- The server won't risk processing a request that might be replayed.
- Upgrade Required
- The client must switch to a different protocol, such as a newer TLS version.
- Precondition Required
- The server requires conditional requests to prevent lost updates.
- Too Many Requests
- You've hit a rate limit. Slow down and retry later.Tip: Look for a Retry-After header telling you how long to wait.
- Request Header Fields Too Large
- The headers (often cookies) are too big.
- Unavailable For Legal Reasons
- Access is blocked for legal reasons, such as a court order.