Key idea
The method says what a request wants to do. The status code says how it went, and its first digit tells you whose problem it is: 2xx worked, 3xx go elsewhere, 4xx the request was wrong, 5xx the server failed.
Methods
- GET fetches something. It should never change anything, so browsers, caches and crawlers repeat it freely.
- POST sends data to be processed: a form, a new order, a login.
- PUT replaces something, PATCH changes part of it, and DELETE removes it.
- HEAD is a GET without the body.
curl -Iuses it to show just the status and headers.
GET, PUT and DELETE are idempotent: doing them twice ends the same as doing them once. POST isn't, which is why a browser warns before sending a form again, and why a double-clicked Pay button can charge twice.
Six status codes
| Code | What it means | Where to look |
|---|---|---|
| 200 OK | It worked | Nowhere |
| 301 Moved Permanently | It's at the URL in the Location header; clients remember that | The Location header; a loop means two rules redirect to each other |
| 404 Not Found | Nothing at that path on this server | The path, and whether you reached the server you meant |
| 500 Internal Server Error | Your app hit an error handling the request | Your app's log, at that time |
| 502 Bad Gateway | Something in front of your app, like a load balancer, got no valid answer from it | Whether your app is running, and listening on 0.0.0.0 and the right port |
| 503 Service Unavailable | The server can't take the request right now | Overload, maintenance, or no healthy copy of your app to send it to |
The difference between 500 and 502 saves the most time. A 500 means your code ran and failed, so the answer is in your log. A 502 means your code never answered, so look at whether it's running and reachable (lesson 1.4.3).
Other codes you'll meet
- 302 and 307: a temporary redirect. 308 is permanent like 301, but keeps the method: a POST stays a POST, where 301 lets clients switch it to GET.
- 401 Unauthorized: you're not logged in, or your token is missing or invalid. 403 Forbidden: you are, but aren't allowed.
- 429 Too Many Requests: slow down; a Retry-After header may say for how long.
- 504 Gateway Timeout: like 502, but your app took too long instead of failing to answer.
Check yourself