Choosing the Right HTTP Status Code

Selecting the right status code improves client behavior, caching efficiency, SEO, and observability. Pick the status class flowchart TD A[Request handled successfully] A -->|Yes| S[2xx] A -->|No| Q{Client problem} Q -->|Yes| C[4xx] Q -->|No| E[5xx] 2xx: the server accepted and completed the request. 4xx: the request is invalid or not allowed. 5xx: the server or an upstream failed to process a valid request. Success details: 200 vs 201 vs 202 vs 204 flowchart TD S[2xx] --> K{Created new resource} K -->|Yes| C201[201 Created] K -->|No| P{Processing deferred} P -->|Yes| C202[202 Accepted] P -->|No| B{Response body present} B -->|Yes| C200[200 OK] B -->|No| C204[204 No Content] 201 Created: the request created one or more resources. Location can identify the primary resource; otherwise, the target URI identifies it. 202 Accepted: processing has not finished and might not occur. Describe the current status and provide a status monitor when available. 200 OK: the request succeeded. The meaning of its content depends on the request method, and the content can have zero length. 204 No Content: the action succeeded and there is no additional content or trailers to send. The flowchart is a starting point, not a complete account of method semantics. A successful response with no content is not automatically a 204. ...

CDN Handbook

HTTP 1xx Informational Codes

The 1xx class indicates the server has received the request headers and the client should proceed. Bodies are not returned. Most clients handle these automatically. Table of 1xx Codes Code Name Summary 100 Continue Client may send the request body. 101 Switching Protocols Protocol upgrade agreed (for example, HTTP to WebSocket). 102 Processing Server has accepted the request, still working (WebDAV). 103 Early Hints Hints for preload before final response (RFC 8297). 100 Continue Used with Expect: 100-continue. Lets large uploads avoid sending a body if the server will reject the request. ...

CDN Handbook

HTTP 2xx Success Codes

The 2xx class means the request was successfully received, understood, and accepted. Table of 2xx Codes Code Name Summary 200 OK Standard success. 201 Created New resource created; Location may be set. 202 Accepted Processing deferred; result not yet available. 203 Non-Authoritative Information Metadata altered by a proxy. 204 No Content Success, no body. 205 Reset Content Client should reset the document view. 206 Partial Content Range response. 207 Multi-Status WebDAV multi-result. 208 Already Reported WebDAV deduplication of results. 226 IM Used Instance-manipulations applied. 200 OK General success. Caching: A 200 response is heuristically cacheable unless the method or explicit cache controls prohibit it. Use available validators such as ETag and Last-Modified to support validation. ...

CDN Handbook

HTTP 3xx Redirection Codes

The 3xx class indicates the client must take additional action to complete the request. Table of 3xx Codes Code Name Summary 300 Multiple Choices Several representations available. 301 Moved Permanently Permanent redirect. 302 Found Temporary redirect (legacy semantics). 303 See Other Redirect to a different URI; use GET. 304 Not Modified Cached representation is still valid. 305 Use Proxy Deprecated. 306 (Unused) Reserved. 307 Temporary Redirect Temporary; method preserved. 308 Permanent Redirect Permanent; method preserved. 300 Multiple Choices Rarely used on the public web; content negotiation is usually implicit. ...

CDN Handbook

HTTP 4xx Client Error Codes

An HTTP 4xx response means the server cannot or will not process the request because of something associated with the request. That does not always mean the human visitor made a mistake: a CDN, firewall, expired credential, malformed link, or client library can also be responsible. Common 4xx codes Code Name Use it when 400 Bad Request The request is malformed or cannot be parsed. 401 Unauthorized Valid authentication credentials are required. 403 Forbidden The request is understood but access is refused. 404 Not Found The target resource cannot be found or is intentionally hidden. 405 Method Not Allowed The method is known but not supported by this resource. 406 Not Acceptable None of the available representations match Accept. 408 Request Timeout The server waited too long for the request. 409 Conflict The request conflicts with the current resource state. 410 Gone The resource was deliberately removed. 412 Precondition Failed An If-* condition evaluated to false. 413 Content Too Large The request body exceeds a limit. 414 URI Too Long The request target is too long. 415 Unsupported Media Type The request format is not supported. 416 Range Not Satisfiable The requested byte range cannot be served. 422 Unprocessable Content Syntax is valid, but the instructions cannot be processed. 425 Too Early Processing replayable early data would be unsafe. 428 Precondition Required A conditional request is required to prevent lost updates. 429 Too Many Requests A rate limit has been exceeded. 431 Request Header Fields Too Large Headers, often cookies, exceed a limit. 451 Unavailable For Legal Reasons Access is denied because of a legal demand. 400 Bad Request Use 400 for malformed syntax, invalid message framing, or a request that cannot be parsed. For an API, return a stable error code and identify invalid fields without exposing secrets or internal stack traces. ...

CDN Handbook

HTTP 5xx Server Error Codes and CDN Troubleshooting

An HTTP 5xx response means a server failed to fulfil an apparently valid request. On a CDN-backed service, “the server” may be an edge node, reverse proxy, load balancer, gateway, or origin. The status alone does not identify the failing layer. 5xx code reference Code Name Typical meaning 500 Internal Server Error The component handling the request failed unexpectedly. 501 Not Implemented The server does not implement the requested method or capability. 502 Bad Gateway A gateway received an invalid upstream response. 503 Service Unavailable The service is temporarily unavailable or overloaded. 504 Gateway Timeout A gateway did not receive an upstream response in time. 505 HTTP Version Not Supported The server does not support the request’s HTTP version. 506 Variant Also Negotiates Content negotiation has a recursive configuration error. 507 Insufficient Storage The server cannot store the representation needed to complete the request. 508 Loop Detected The server detected an infinite loop while processing the request. 510 Not Extended Further extensions are required to fulfil the request. 511 Network Authentication Required The client must authenticate to gain network access. 500 Internal Server Error 500 is a general failure when a more specific status is not suitable. Common causes include an unhandled exception, invalid configuration, exhausted memory, failed dependency, or file-permission error. ...

CDN Handbook

HTTP Redirects: 301 vs 302 vs 303 vs 307 vs 308

An HTTP redirect tells a client to make another request at a location named in the Location response header. The main choices are whether the move is permanent and whether the redirected request must preserve its method and body. Redirect decision table Situation Use Method handling Permanent move for a normal page or GET resource 301 A user agent may change POST to GET. Temporary move for a normal page or GET resource 302 A user agent may change POST to GET. Result of a POST is available at a separate GET URL 303 The follow-up request is GET or HEAD. Temporary move that must preserve the method and body 307 Method and body are preserved. Permanent move that must preserve the method and body 308 Method and body are preserved. For GET and HEAD, 301 and 302 are usually sufficient. For an API request such as POST, PUT, or PATCH, use 307 or 308 when replaying the same method and body at the destination is intentional and safe. ...

CDN Handbook