HTTP status codes
TL;DR
Every HTTP response carries a three-digit status code. The first digit is the category (2xx worked, 3xx redirect, 4xx you did something wrong, 5xx the server did). During a test the exact code often tells you more than the page content does.
What it is
When your browser or your tools ask a web server for something, the server answers with a status code: a three-digit number saying how the request went. You already know 404. There are many more, and they follow a simple pattern.
How it works
The first digit sorts every code into one of five families:
| Range | Family | Means |
|---|---|---|
| 1xx | Informational | Received, still going. Rare day to day. |
| 2xx | Success | It worked. 200 OK, 201 Created, 204 No Content. |
| 3xx | Redirect | Go elsewhere. 301/302, 304 Not Modified. |
| 4xx | Client error | Your request was wrong or not allowed. |
| 5xx | Server error | The server broke trying to handle it. |
How to test with them
The codes that earn their keep are usually 4xx and 5xx, because they leak how the app thinks:
- 401 vs 403 — 401 means “who are you?” (not authenticated); 403 means “I know who you are, and no” (authenticated, not allowed). That tells you whether you need creds or a privilege.
- 403 here, 200 there — a quick map of what is protected and what is not.
- 500 after odd input — the server hit something it did not expect. Worth a closer look at what you sent.
- 302 to a login page — an easy way to tell protected pages from public ones at scale.
Seeing the raw code with curl:
curl -s -o /dev/null -w "%{http_code}\n" https://example.com/
Reference: MDN’s full status code list.