Mischief Managed: A Harry Potter Guide to HTTP Response Codes
Have you ever wondered what actually happens behind the scenes when you click a link or type a website address? It feels like magic—and honestly, it’s not that different from sending a message at Hogwarts.
To understand how exactly this works, let’s imagine your web browser (like Chrome or Safari) is Harry Potter, and the website’s server is the Hogwarts Library.
When Harry wants a book, he sends an owl with a note. What happens next is exactly how the web communicates.
What is a HTTP response?
An HTTP Response is the package of data the server (the waiter) brings back to your browser (the customer) after processing your request. or If we have to describe simply, the HTTP Response is the owl flying back to Harry with Madam Pince’s reply.
When Harry opens the envelope, it contains three things:
- The Body: The actual magic book Harry asked for (the HTML/CSS/JavaScript of the webpage), or simply, the data that makes up the webpage you see on your screen.
- The Status Line: A quick note taped to the top telling Harry if the errand was successful, or simply, A quick progress report (this includes the HTTP response/status code).
- The Headers: The “metadata” on the back of the envelope—the date, the official Hogwarts library stamp, and a note saying “Warning: This book contains moving pictures.”, or simply put, Metadata about the response, like the date, what kind of server it is, and the type of content being sent back.
but now, the question arises,
What is an HTTP status code?
Madam Pince, the Hogwarts librarian, is far too busy to write long letters to every student. Instead, she uses a simple 3-digit shorthand code right at the top of her note to instantly tell Harry how his request went. These 3-digit numbers are HTTP Status Codes. The very first digit tells Harry what kind of situation he is dealing with:
In general we can define it as- An HTTP Response Code (often called a status code) is a 3-digit number included right at the top of that response. It acts as a universal shorthand that instantly tells your browser exactly how the request went.
What are the various Status Codes we see, in our day-to-day life?
1XX: Informational Responses –
The 1xx Informational codes are the web’s way of saying, “I heard you, I’m working on it, so don’t close the page yet!” If we have to explain more clearly, Putting on the Sorting Hat. It doesn’t sort you instantly; it sits on your head muttering, “Hmm, let’s see… where to put you…” while you wait.
There are multiple 1xx status codes, they are:
- 100 Continue
This happens in two parts. The browser asks if it’s okay to send a huge file, and the server says go ahead.
The Browser’s Request:
POST /upload-video HTTP/1.1
Host: website.com
Content-Length: 2147483648
Expect: 100-continue
The Server’s Interim Response:
HTTP/1.1 100 Continue
(After this, the browser immediately starts transmitting the actual video file data).
101 Switching Protocols
This code is used when a browser wants to upgrade a standard web connection to a permanent, live WebSocket connection (like for a chat room).
The Browser’s Request:
GET /chat HTTP/1.1
Host: website.com
Upgrade: websocket
Connection: Upgrade
The Server’s Response:
HTTP/1.1 101 Switching Protocols
Upgrade: websocket
Connection: Upgrade
(The HTTP connection is now closed, and a live WebSocket channel is officially open).
102 Processing
This is an interim response sent back by the server during a very long task to stop the browser from timing out while it waits for the final results.
The Server’s Interim Response:
HTTP/1.1 102 Processing
(The server sends this, keeps working on the heavy task behind the scenes, and will send a 200 OK code several seconds later when the job is actually finished).
103 Early Hints
This tells the browser to start downloading critical styles and fonts while the server takes its time building the actual HTML webpage.
The Server’s Interim Response:
HTTP/1.1 103 Early Hints
Link: </styles/main.css>; rel=preload; as=style
Link: </fonts/inter.woff2>; rel=preload; as=font
(While the browser goes off to fetch main.css, the server finishes gathering database data and will send the standard 200 OK code with the full HTML right after).
2XX: Successful Responses-
The 2xx status codes mean your browser’s request was successfully received, understood, and accepted by the server. Think of this as successfully casting a spell on the first try. You swish and flick your wand, say “Wingardium Leviosa,” and the feather instantly floats into the air exactly like you wanted.
There are multiple 2xx status codes, they are:
200 OK
The standard “success” code. The server found what you asked for and handed it over.
Code Example:
HTTP/1.1 200 OK
Content-Type: text/html
<!DOCTYPE html>
<html><body><h1>Welcome to Hogwarts</h1></body></html>
201 Created
Your request succeeded, and a brand-new resource was built on the server because of it (like a user successfully signing up).
Code Example:
HTTP/1.1 201 Created
Location: /users/harry_potter
Content-Type: application/json
{"status": "User profile successfully created"}
202 Accepted
The server accepted your request, but it is going to process it in the background later. It hasn’t finished yet, but it’s queued up.
Code Example:
HTTP/1.1 202 Accepted
Content-Type: application/json
{"task_id": "9¾", "status": "Video processing has started in the background"}
204 No Content
The request was completely successful, but the server doesn’t need to send any data or text back in the body (common for hitting a “Delete” button).
Code Example:
HTTP/1.1 204 No Content
205 Reset Content
The server tells the browser to completely clear or clear out whatever form the user is currently looking at (like resetting a registration form back to blank).
Code Example:
HTTP/1.1 205 Reset Content
206 Partial Content
The browser only asked for a chunk of a massive file (like a specific 10-second slice of a long video), and the server is delivering just that specific piece.
Code Example:
HTTP/1.1 206 Partial Content
Content-Range: bytes 0-1023/2048
Content-Length: 1024
207 Multi-Status
Used in WebDAV environments. If you send a request that performs multiple distinct operations at once, this response bundles several different individual status codes inside an XML body.
Code Example:
HTTP/1.1 207 Multi-Status
Content-Type: text/xml
<multistatus xmlns="DAV:">
<response>
<href>/file1.txt</href>
<status>HTTP/1.1 200 OK</status>
</response>
</multistatus>
208 Already Reported
Used inside a 207 Multi-Status response to tell the browser, “Hey, I already processed and listed this specific folder path earlier in this message, so I’m not going to repeat myself.“
Code Example:
<response>
<href>/duplicate-folder/</href>
<status>HTTP/1.1 208 Already Reported</status>
</response>
226 IM Used
The server is sending a modified version of a cached resource. Instead of sending the entire webpage, it only sends the exact edits (the deltas) that have changed since the last time you downloaded it.
Code Example:
HTTP/1.1 226 IM Used
Delta-Base: "v1-cache-hash"
3XX: Redirection Messages-
The 3xx status codes mean that the resource you are looking for has moved, and your browser needs to take an extra step to go to a different address to find it. Think of this as the Moving Staircases at Hogwarts. You try to walk down a specific corridor to get to your classroom, but the staircase suddenly shifts gears mid-walk, forcing you to follow a completely different pathway to reach your final destination.
There are multiple 3xx status codes, they are:
300 Multiple Choices
The request has more than one possible response. The browser or user must choose which one they want (e.g., choosing between different video formats or language versions).
Code Example:
HTTP/1.1 300 Multiple Choices
Content-Type: application/json
{
"choices": [
{"lang": "en", "url": "/en/hogwarts"},
{"lang": "fr", "url": "/fr/hogwarts"}
]
}
301 Moved Permanently
The webpage has been permanently assigned a new URL. Any future requests should use the new link provided in the Location header.
Code Example:
HTTP/1.1 301 Moved Permanently
Location: https://new-hogwarts-site.com/library
302 Found(Temporary Redirect)
The webpage is temporarily living at a different URL, but it will return to its old address in the future. The browser should keep using the original URL next time.
Code Example:
HTTP/1.1 302 Found
Location: https://temporary-classroom.com/dada
303 See Other
The server found the data you requested, but it wants you to fetch it using a distinct GET request at a different URL (very common after submitting a form so you don’t resubmit it by accident).
Code Example:
HTTP/1.1 303 See Other
Location: /payment-success-page
304 Not Modified
The server tells your browser, “The webpage hasn’t changed since the last time you visited, so just load your local cached copy to save time and data.“
Code Example:
HTTP/1.1 304 Not Modified
Cache-Control: max-age=3600
305 Use Proxy
Deprecated/Old. It used to tell the browser that the requested resource could only be accessed by going through the specific proxy server listed in the location header.
Code Example:
HTTP/1.1 305 Use Proxy
Location: http://my-secure-proxy.com:8080
306 Switch Proxy
No longer used. This was originally designed to tell the browser that subsequent requests should use a specified proxy, but it is now completely dead and reserved.
Code Example:
HTTP/1.1 306 Switch Proxy
307 Temporary Redirect
This acts exactly like a 302 Found, but with one major rule: the browser must not change the HTTP method used. If you sent a POST request with form data, you must send that exact same POST request to the new temporary URL.
Code Example:
HTTP/1.1 307 Temporary Redirect
Location: https://backup-api.com/submit-form
308 Permanent Redirect
This acts exactly like a 301 Moved Permanently, but with the same strict rule as 307: the browser must keep the exact same HTTP method (like POST) when hitting the new permanent address.
Code Example:
HTTP/1.1 308 Permanent Redirect
Location: https://main-api.com/v2/submit-form
4XX: Client Error Responses-
The 4xx status codes mean that something went wrong with the request sent by the browser. The server is working completely fine, but the user has made an error—like typing a URL wrong, trying to access a page without logging in, or requesting something they aren’t allowed to see. Imagine Harry Potter sneaking into the Restricted Section of the Hogwarts Library at night. He doesn’t have a signed permission slip from a professor, and he’s looking for a book that shouldn’t be touched. Madam Pince catches him instantly, points a strict finger, and kicks him out. The library is perfectly intact, but Harry made a mistake by breaking the rules.
There are multiple 4xx status codes, they are:
400 Bad Request
The server cannot understand the request because the syntax is garbled, corrupt, or missing vital information.
Code Example:
HTTP/1.1 400 Bad Request
Content-Type: application/json
{"error": "Malformed JSON payload. Missing closing bracket."}
401 Unauthorized
The requested page requires authentication. You must provide valid credentials (like a username and password) to see it.
Code Example:
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Basic realm="Secure Admin Area"
403 Forbidden
The server knows exactly who you are, but you absolutely do not have permission to view this resource. Unlike a 401, logging in won’t help you here.
Code Example:
HTTP/1.1 403 Forbidden
Content-Type: text/plain
Error: You do not have administrator privileges to access this directory.
404 Not Found
The most famous code on the web. The server is running fine, but the specific file or URL path you requested simply does not exist.
Code Example:
HTTP/1.1 404 Not Found
Content-Type: text/html
<h1>404: The page you are looking for has vanished into thin air.</h1>
405 Method Not Allowed
The target URL exists, but it doesn’t accept the specific HTTP method you used (for example, trying to POST data to a static page that only allows GET requests).
Code Example:
HTTP/1.1 405 Method Not Allowed
Allow: GET, HEAD
408 Request Timeout
The server got tired of waiting for the browser to finish sending its request and decided to close the connection to save resources.
Code Example:
HTTP/1.1 408 Request Timeout
Connection: close
409 Conflict
The request cannot be completed because it conflicts with the current state of the server (like trying to sign up with an email address that is already registered in the database).
Code Example:
HTTP/1.1 409 Conflict
Content-Type: application/json
{"error": "Username 'HarryPotter' is already taken."}
410 Gone
Similar to a 404, but intentional. The resource used to be here, but it has been permanently deleted and will never come back.
Code Example:
HTTP/1.1 410 Gone
Connection: close
415 Unsupported Media Type
The server refuses to process the request because the format of the data being sent isn’t supported (like trying to upload a .txt file to an image-only profile picture uploader).
Code Example:
HTTP/1.1 415 Unsupported Media Type
Accept: image/jpeg, image/png
422 Unprocessable Entity
The request syntax is completely correct, but the server cannot process the contained instructions because the data inside makes no logical sense (like trying to submit a form where your birth year is set to 2099).
Code Example:
HTTP/1.1 422 Unprocessable Entity
Content-Type: application/json
{"errors": {"age": "Age cannot be a negative number."}}
429 Too Many Requests
Rate limiting. The user has sent too many requests in a short window of time, and the server is blocking them temporarily to protect itself from crashing.
Code Example:
HTTP/1.1 429 Too Many Requests
Retry-After: 3600
Fun Fact: There is a famous joke code in the official HTTP specifications: 418 I’m a Teapot. It was created as an April Fools’ joke in 1998 to show how a teapot should refuse an attempt to brew coffee, but it remains a real, valid code to this day.
5XX: Server Error Responses-
The 5xx status codes mean that the client (the browser) did absolutely nothing wrong, but the server encountered a major internal glitch, crashed, or ran out of resources while trying to process the request. Imagine you throw down your Floo powder, step into the fireplace, and state your destination perfectly clearly. Suddenly, the entire magical grid glitches, green sparks shoot out wildly, and you get thrown out of the wrong grate into Knockturn Alley. It wasn’t your fault, your pronunciation was flawless. The underlying magical network itself just suffered a system-wide crash.
There are multiple 5xx status codes, they are:
500 Internal Server Error
The generic “catch-all” error code for when the server encounters an unexpected condition or software bug that prevents it from fulfilling the request.
Code Example:
HTTP/1.1 500 Internal Server Error
Content-Type: application/json
{"error": "NullPointerException: Database connection failed unexpectedly."}
502 Bad Gateway
The server you connected to was acting as a proxy or “middleman” gateway, and it received an invalid, garbled response from the main backend server it tried to talk to.
Code Example:
HTTP/1.1 502 Bad Gateway
Content-Type: text/html
<h1>502 Bad Gateway: Main application server did not respond correctly.</h1>
503 Service Unavailable
he server is currently incapable of handling the request. This is almost always a temporary state caused by the server being completely overloaded with too much traffic or being down for scheduled maintenance.
Code Example:
HTTP/1.1 503 Service Unavailable
Retry-After: 120
504 Gateway Timeout
Like the 502 error, the server you hit was acting as a middleman. However, instead of getting a bad response from the backend, the backend took way too long to respond, and the gateway server ran out of patience and gave up.
Code Example:
HTTP/1.1 504 Gateway Timeout
Connection: close
505 HTTP Version Not Supported
The server refuses to handle the request because it doesn’t support the specific version of the HTTP protocol that the browser used to send it (e.g., a very old legacy server trying to read a modern HTTP/3 request).
Code Example:
HTTP/1.1 505 HTTP Version Not Supported
The next time you encounter a broken link or an unexpected glitch online, you don’t need a magic wand to figure out what went wrong. Just look at that little 3-digit number at the top of the screen. Whether it’s the server telling you everything went perfectly (200 OK), a moving staircase rerouting your path (301 Moved Permanently), Madam Pince kicking you out of the Restricted Section (403 Forbidden), or the Floo Network crashing entirely behind the scenes (500 Internal Server Error) etc, you can always check!
Happy coding, and may your browser never return a 500!
Hi, I’m Abhilasha Kundu! I’m currently completing B.Tech, exploring the world of web development. I started writing in this blog to document what I learn, break down complex tech concepts, and share practical insights along the way.