Skip to content
EasyToDecode

HTTP status codes explained: what 4xx and 5xx errors mean

A 4xx code means the server thinks your request is the problem: a wrong address, a missing sign-in or too many requests. A 5xx code means the server or something behind it failed. 502, 503 and 504 point to a broken, busy or slow server, not your device.

By EasyToDecode editorial teamPublished October 10, 2026

Every time a browser or app asks a server for something, the server answers with a three-digit status code. Most of the time you never see it. You only notice when the answer is an error, and the page shows a bare number such as 403 or 502. The first digit does most of the work: it tells you whether the problem is with the request or with the server.

The five classes of status codes

MDN, the reference Mozilla maintains for web developers, groups codes by their first digit:

  • 1xx, informational: the request was received and is still being processed. You rarely see these.

  • 2xx, success: the request worked. 200 OK is the usual one.

  • 3xx, redirection: the content lives somewhere else and the browser is sent there.

  • 4xx, client error: the server thinks the request itself is wrong.

  • 5xx, server error: the server, or something it depends on, failed.

The HTTP standard, RFC 9110, puts the split plainly. A 4xx code means "the client seems to have erred", while a 5xx code means "the server is aware that it has erred". "Client" here means whatever sent the request: your browser, a phone app, a script.

Common 4xx codes and what they usually mean

  • 400 Bad Request: the server could not process the request because something about it looks malformed, such as a broken link, a corrupted form or an odd character in the address.

  • 401 Unauthorized: MDN notes that this really means "unauthenticated". You need to sign in, or your session has expired.

  • 403 Forbidden: the server knows who you are but will not give you this page. Signing in again rarely helps; you need permission.

  • 404 Not Found: the server cannot find the resource. The address may have a typo, or the page may have moved or been removed. MDN adds that some servers send 404 instead of 403 to hide that a page exists.

  • 408 Request Timeout: the server closed a connection that sat idle. A reload usually fixes it.

  • 429 Too Many Requests: you, or your network, sent too many requests in a short time, and the server is rate limiting. Waiting is the fix.

Common 5xx codes, including 502, 503 and 504

  • 500 Internal Server Error: a generic failure. MDN describes it as a situation the server "does not know how to handle". The cause is on the site's side.

  • 502 Bad Gateway: the server you reached was acting as a go-between (a gateway or proxy) and got an invalid response from the server behind it.

  • 503 Service Unavailable: the server is not ready to handle the request, often because it is down for maintenance or overloaded. MDN says this code is meant for temporary conditions, and the server may send a Retry-After header with an estimated recovery time.

  • 504 Gateway Timeout: the go-between server did not get an answer from the server behind it in time.

Many sites sit behind a front server, such as a load balancer or a content delivery network, that passes your request to the application doing the real work. That is why three of these codes mention a gateway.

502 vs 503 vs 504: a quick way to tell them apart

  • 502: the back-end server answered, but with something broken or unexpected. Think "bad reply".

  • 503: the server says it cannot take requests right now. Think "closed for now".

  • 504: the back-end server never answered in time. Think "no reply".

From your side, all three mean the same thing: the problem is not your device, your password or your browser. Reloading after a minute or two is reasonable. Clearing cookies or reinstalling the browser is unlikely to help.

Where you will see these codes

On a web page, the code is often shown in large type, sometimes with the site's own branded error page. In apps, it may be buried in a message like "Request failed with status code 503". In server logs, it is a field on every line. Here is a sample line in the Common Log Format that Apache documents (synthetic, from a fictional Northgate Store site):

203.0.113.24 - - [09/Oct/2026:21:14:12 -0700] "GET /checkout HTTP/1.1" 504 312

Read it left to right: the visitor's IP address, two empty fields shown as hyphens, the time, the request line in quotes, the status code (504) and the size of the reply in bytes. The Apache documentation notes that codes beginning with 4 are errors caused by the client and codes beginning with 5 are errors in the server. If you run the site, our guide to reading Nginx and Apache error logs shows how to find the matching line in the error log.

What to try first, by code

If you see a 4xx code:

  1. Check the address for typos, extra characters or a cut-off link.

  2. For 401, sign out and sign in again.

  3. For 403, ask the site owner or your account admin whether you should have access.

  4. For 404, go to the site's home page and search for the content instead.

  5. For 429, stop retrying and wait several minutes. Rapid reloads only add more requests.

If you see a 5xx code:

  1. Wait a minute, then reload once.

  2. Check whether the site or app has a status page or social account reporting an outage.

  3. Try again later rather than repeatedly. For a payment or form submission, check your email or account before resubmitting, so you do not pay or apply twice.

  4. If it keeps happening, report it to the site with the details below.

What to include when you report an error

Support teams can act faster with specifics. Note:

  • The exact code and any text on the page.

  • The full address you were trying to open.

  • The date, time and time zone.

  • What you clicked or submitted just before.

  • Whether it happens on another device or network.

Before pasting anything from a log, remove passwords, tokens and personal details. Our guide on sharing logs safely walks through what to strip out.

Get the error explained in plain English

EasyToDecode is launching soon. You will be able to paste an error page, a screenshot or a log file, and it will point to the line that matters, quote the status code and its context, flag what is missing, and suggest what to try first and what to ask the site's support. See how it works or join the waitlist to hear when it opens.

Questions

Is a 4xx error my fault?

Not always, but the server thinks something about the request is wrong: the address, your sign-in, your permissions or how often you are asking. Check the link and your account first.

What is the difference between 502 and 504?

Both come from a go-between server. With 502 it got an invalid reply from the server behind it; with 504 it got no reply in time.

How long does a 503 error last?

There is no fixed length. MDN says 503 is meant for temporary conditions, and the server may include a Retry-After header with an estimated wait.

What is the difference between 401 and 403?

401 means you need to sign in (MDN calls it "unauthenticated"). 403 means the server knows who you are but you do not have permission.

Sources

  1. MDN Web Docs: HTTP response status codes (checked October 10, 2026)
  2. RFC Editor: RFC 9110, HTTP Semantics (checked October 10, 2026)
  3. Apache HTTP Server 2.4: Log Files (checked October 10, 2026)

About this guide. Prepared by the EasyToDecode editorial team. Facts were checked against the official sources listed above (last checked October 10, 2026).

How we prepare and check our guides

General information, not legal, financial or tax advice. Rules differ by state, province and territory and change over time; check the sources and, for decisions with legal or financial consequences, a qualified professional.