HTTP status codes
status code, response code, 404, 500, 2xx, 4xx, 5xxDefinition
The three-digit number an HTTP response opens with, saying how the request went: 2xx it worked, 3xx look elsewhere, 4xx you asked wrong (or may not), 5xx we failed — the first digit is the class a client can act on without knowing the rest
Defined in RFC 9110 and registered at IANA; the ones a web team meets are a couple of dozen. The class is the contract: a browser follows a 3xx, a crawler drops a 410 and keeps trying a 503, a script retries a 5xx and does not retry a 4xx. The two worth getting exactly right are 401 against 403 (not signed in, against signed in and refused) and 403 against 404 (refused, against not there) — the second is a privacy decision, since a 403 admits the thing exists. On this site a private document is a 404 to a visitor for that reason, and a refused sign-in is a 403 with a named reason so the person knows they were refused rather than lost.
The status is for the machine and the body is for the person; a route
that answers 500 with a stack trace has confused the two, and one that
answers 200 with { error: true } has confused them the other way.
The reference page lists the codes by
class with what each means here.