ALL DEVELOPER TOOLS56
HTTP Status Codes
HTTP Status Codes — The Full IANA Registry
Every registered code with its RFC, plus the nginx and Cloudflare codes no standard defines.
About HTTP Status Codes
A status code is three digits and a whole argument about what the server meant. This page is the full IANA registry: every registered code from 100 to 511 with its reason phrase, the RFC that defines it, and a plain-English description of when a server sends it. Search matches the number, the phrase and the description, so you can look up 429 or type captive portal and land on the right entry. Where a property is defined by the specification it is stated rather than implied. Twelve status codes are heuristically cacheable — a cache may reuse them with no freshness header at all — and those carry a flag; nothing here claims a response cannot be cached, because that is decided by headers rather than by the code. Every 3xx says what happens to the request method, which is the difference between a 301 that silently turns your POST into a GET and a 308 that does not. The codes no standard defines, from nginx's 499 to Cloudflare's 5xx range to LinkedIn's 999, sit in a separate labelled group, because they are in your logs and in no RFC.
Questions
What is the difference between 502 and 504?
Both come from something in front of your application, and the difference tells you where to look. 502 Bad Gateway means the proxy got an invalid response: the upstream process crashed, is not listening, or returned something that is not HTTP. 504 Gateway Timeout means the upstream was reachable and simply did not answer in time. So 502 sends you to crash logs and process supervision, while 504 sends you to slow queries, connection pools and timeouts. Cloudflare splits the timeout case further — 522 is a connection that never established, 524 is one that established and then produced nothing.
Why did my POST turn into a GET after a redirect?
Because you redirected with a 301 or a 302. The specification permits a user agent to change the method to GET on those two, for historical reasons, and every browser does, so the body is dropped and the request arrives as a GET. 303 is the same behaviour stated deliberately: the follow-up is always a GET, which is what makes the POST/redirect/GET pattern work. If you need the method and body to survive, use 307 for a temporary move and 308 for a permanent one — both forbid the rewrite. Every 3xx on this page carries a chip saying which of those it is.
Is 418 I'm a teapot a real HTTP status code?
No. RFC 2324 was an April Fools' joke from 1998 defining the Hyper Text Coffee Pot Control Protocol, and 418 came from there. It is not part of HTTP. What is real is that so many servers and frameworks implemented the joke that RFC 9110 now reserves 418 as unusable, so nothing legitimate can ever take the number. That is how it appears here: registered, with the phrase (Unused), and the teapot explained in the description. Sending it from a real service is a way of returning an error that no client library will understand.
Where do 520 and 499 come from? They are not in any RFC.
They are vendor codes. 499 is nginx's, logged when the client hangs up before nginx can answer — it is the commonest non-standard code in a real access log and it is usually not a server fault. The 520 to 530 range is Cloudflare's, describing what went wrong between the edge and your origin. This page keeps all of them in a separate group below a rule, each labelled with the software that emits it, and the Include vendor codes checkbox hides them. They are worth knowing and they are not HTTP, and merging the two lists would make the page more convenient and less true.
Can I paste a URL in and have it tell me the status?
No — this is a reference table, not a checker. There is no field to type a site into, and the page makes no network requests at all: every entry ships with the page and is searched locally. That is deliberate. A status checker has to send your URL somewhere, and a URL is very often the interesting part of a bug report — the token in the query string, the internal hostname. If you want the real status of a request, curl -I or your browser's network panel will tell you, and this page will tell you what the answer means.
Is my file uploaded to a server?
No. Transmute processes everything locally in your browser using JavaScript and WebAssembly. Your files never leave your device — there is no server, no upload, no cloud processing.