Methods and the status codes that matter

Reading · 5 min · Module 6, lesson 2 of 416 min left in this module

Module 6 · HTTP and HTTPSLesson 2 of 4

Goal: Choose the right method for a request, and know where to look from a response's status code.

Key idea

The method says what a request wants to do. The status code says how it went, and its first digit tells you whose problem it is: 2xx worked, 3xx go elsewhere, 4xx the request was wrong, 5xx the server failed.

Methods

  • GET fetches something. It should never change anything, so browsers, caches and crawlers repeat it freely.
  • POST sends data to be processed: a form, a new order, a login.
  • PUT replaces something, PATCH changes part of it, and DELETE removes it.
  • HEAD is a GET without the body. curl -I uses it to show just the status and headers.

GET, PUT and DELETE are idempotent: doing them twice ends the same as doing them once. POST isn't, which is why a browser warns before sending a form again, and why a double-clicked Pay button can charge twice.

Six status codes

CodeWhat it meansWhere to look
200 OKIt workedNowhere
301 Moved PermanentlyIt's at the URL in the Location header; clients remember thatThe Location header; a loop means two rules redirect to each other
404 Not FoundNothing at that path on this serverThe path, and whether you reached the server you meant
500 Internal Server ErrorYour app hit an error handling the requestYour app's log, at that time
502 Bad GatewaySomething in front of your app, like a load balancer, got no valid answer from itWhether your app is running, and listening on 0.0.0.0 and the right port
503 Service UnavailableThe server can't take the request right nowOverload, maintenance, or no healthy copy of your app to send it to

The difference between 500 and 502 saves the most time. A 500 means your code ran and failed, so the answer is in your log. A 502 means your code never answered, so look at whether it's running and reachable (lesson 1.4.3).

Other codes you'll meet
  • 302 and 307: a temporary redirect. 308 is permanent like 301, but keeps the method: a POST stays a POST, where 301 lets clients switch it to GET.
  • 401 Unauthorized: you're not logged in, or your token is missing or invalid. 403 Forbidden: you are, but aren't allowed.
  • 429 Too Many Requests: slow down; a Retry-After header may say for how long.
  • 504 Gateway Timeout: like 502, but your app took too long instead of failing to answer.

Check yourself

After a deploy, every page returns 502, and your app's log is empty. Where do you look first?
Which method should a 'delete my account' button send?

In the docs