LearnThatStack Ace your next interview
API Design · question
Question 9 of 110

What are HTTP status codes and give examples of common ones?

beginner
← All API Design questions
Re-explain

HTTP status codes are three-digit numbers that indicate the result of an HTTP request. They are grouped into five categories:

1xx - Informational:

  • 100 Continue

2xx - Success:

  • 200 OK: Request successful
  • 201 Created: Resource successfully created
  • 204 No Content: Successful but no content to return

3xx - Redirection:

  • 301 Moved Permanently
  • 304 Not Modified

4xx - Client Error:

  • 400 Bad Request: Invalid request syntax
  • 401 Unauthorized: Authentication required
  • 403 Forbidden: Access denied
  • 404 Not Found: Resource doesn't exist
  • 409 Conflict: Request conflicts with current state

5xx - Server Error:

  • 500 Internal Server Error
  • 503 Service Unavailable
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

The diagram below the answer is the concept . Jump to it ↓

Tailored explanation · switch back to · ·
What should the new diagram focus on?
Guided practice for API Design One question at a time. Answer out loud, get graded, see what you missed.
How well did you know this?
AI:

Saved in this browser - sign in to keep your review list.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Interview lens How interviewers actually use this question

Likely follow-ups

  • When would you return 401 and when 403? 401 means the server doesn't know who you are; 403 means it knows and still refuses. Logging in again only helps with a 401.
  • A POST creates a new order. What status code and headers do you send back? 201 Created with a Location header pointing at the new resource, often with the created representation in the body.
  • How does 304 Not Modified work, and what does the client have to send to get one? A conditional GET with If-None-Match carrying an ETag, or If-Modified-Since. The server replies 304 with no body and the client reuses its cache.
  • A request fails validation. Which status do you return, and what goes in the body? 400, or 422 in some APIs, plus a structured body naming each bad field and why, so the client can fix it without guessing.
  • Which status codes should a client retry automatically, and which should it leave alone? 503 and 429 are worth retrying with backoff and Retry-After. Most 4xx will fail the same way again. Retrying a non-idempotent POST risks duplicates.

What you can say

  1. A status code is the three-digit number the server sends back to say how a request went, and the first digit puts it in one of five groups.
  2. 1xx is informational, like 100 Continue, and you rarely see it. 2xx means success: 200 OK, 201 Created for a new resource, 204 No Content when there's nothing to return.
  3. 3xx is redirection, like 301 Moved Permanently, or 304 Not Modified, which tells the client its cached copy is still good.
  4. 4xx means the client got something wrong: 400 for a malformed request, 401 when you're not authenticated, 403 when you are but still aren't allowed, 404 when it doesn't exist, 409 for a conflict.
  5. 5xx means the server failed, like 500 Internal Server Error for an unexpected crash, or 503 Service Unavailable when it's overloaded or down for maintenance.
  6. In practice the 4xx versus 5xx split matters most, since it tells clients and monitoring whose fault it was, so I'd never send 200 with an error hidden in the body.

Weak answers to avoid

  • Recites a list of codes with no grouping A memorized list doesn't show understanding. Lead with the five classes and what each first digit means, then give two or three codes per class.
  • Mixes up 401 and 403 This is the most common slip. 401 means the server can't tell who you are; 403 means it knows and refuses. Getting it wrong reads as shaky on auth basics.
  • Says errors can return 200 with a message Clients, caches and monitoring read the status line, not the body. A 200 on failure hides the error, so send the 4xx or 5xx that fits.
  • Uses 500 for bad input A 500 says the server broke, which pages the on-call team and invites retries. Invalid input from the client is a 4xx, usually 400.
Interview lens

Likely follow-ups, what you can say, and the weak answers to avoid.

Sign in free to open it Free account - the lens opens as soon as you're back.

Want a quick review of the fundamentals? See the API Design cheatsheet.

← Back to all API Design questions
Pro · $10/mo

90 of 110 API Design answers are in Pro.

Full answers, code samples, and AI explanations that go simpler or deeper. Cancel anytime.

  • Full answers + code
  • AI explanations, simpler or deeper
  • 1,000 AI credits / month
  • Cancel anytime