An HTTP 4xx response means the server cannot or will not process the request because of something associated with the request. That does not always mean the human visitor made a mistake: a CDN, firewall, expired credential, malformed link, or client library can also be responsible.
Common 4xx codes Code Name Use it when 400 Bad Request The request is malformed or cannot be parsed. 401 Unauthorized Valid authentication credentials are required. 403 Forbidden The request is understood but access is refused. 404 Not Found The target resource cannot be found or is intentionally hidden. 405 Method Not Allowed The method is known but not supported by this resource. 406 Not Acceptable None of the available representations match Accept. 408 Request Timeout The server waited too long for the request. 409 Conflict The request conflicts with the current resource state. 410 Gone The resource was deliberately removed. 412 Precondition Failed An If-* condition evaluated to false. 413 Content Too Large The request body exceeds a limit. 414 URI Too Long The request target is too long. 415 Unsupported Media Type The request format is not supported. 416 Range Not Satisfiable The requested byte range cannot be served. 422 Unprocessable Content Syntax is valid, but the instructions cannot be processed. 425 Too Early Processing replayable early data would be unsafe. 428 Precondition Required A conditional request is required to prevent lost updates. 429 Too Many Requests A rate limit has been exceeded. 431 Request Header Fields Too Large Headers, often cookies, exceed a limit. 451 Unavailable For Legal Reasons Access is denied because of a legal demand. 400 Bad Request Use 400 for malformed syntax, invalid message framing, or a request that cannot be parsed. For an API, return a stable error code and identify invalid fields without exposing secrets or internal stack traces.
...