The five classes
Status codes answer one question: who is at fault and what should the client do next? 1xx = in progress, 2xx = success, 3xx = go elsewhere, 4xx = client's fault, 5xx = server's fault. Restful APIs and crawlers both depend on you answering honestly.
The codes that matter daily
| Code | Meaning | Notes |
|---|---|---|
| 200 | OK | GET/PUT/PATCH success |
| 201 | Created | include a Location header |
| 204 | No content | DELETE success; must have empty body |
| 301 / 308 | Moved permanently | 308 preserves method; 301 may re-POST as GET |
| 302 / 307 | Moved temporarily | use for flows that will revert |
| 304 | Not modified | with ETag/If-None-Match; saves the full transfer |
| 400 / 422 | Bad request / unprocessable | 400 = malformed; 422 = well-formed but invalid |
| 401 / 403 | Unauthenticated / unauthorized | 401 = log in; 403 = logged in, still denied |
| 404 | Not found | also the honest answer for "exists but none of your business" — 403 leaks existence |
| 409 | Conflict | concurrent update / duplicate key |
| 429 | Too many requests | send Retry-After |
| 500 / 502 / 503 / 504 | Server errors | bug / bad gateway / overloaded / timeout |
Where APIs go wrong
- Everything is 200 with
{"error": ...}in the body — breaks retry logic, monitoring, and every HTTP client's assumptions. - 500 for validation errors — a client-fixable problem paging an on-call engineer.
- Redirect chains — 301 then 302 then 301: each hop costs a round trip; consolidate, and never redirect POST without 307/308.
SEO angles
Google treats 4xx/5xx honestly: a 404 drops the URL from index (fine for removed pages), but a soft-404 — a "200 OK" page saying "not found" — wastes crawl budget and confuses signals. 301 passes equity; 302 tells Google the target is temporary. 503 with Retry-After is the correct "down for maintenance" signal; repeated 500s deindex content.
Look up any code with response-class explanations in the HTTP Status Codes reference.