Status codes and headers
Read a response: status classes, the headers that matter and how caching is controlled.
Status codes by class
- 2xx success:
200 OK,201 Created,204 No Content. - 3xx redirection:
301 Moved Permanently,302 Found,304 Not Modified. - 4xx client error:
400 Bad Request,401 Unauthorized,403 Forbidden,404 Not Found,429 Too Many Requests. - 5xx server error:
500 Internal Server Error,502 Bad Gateway,503 Service Unavailable.
Rule of thumb: 4xx means the request is the problem, 5xx means the server is the problem.
A response
HTTP/2 200
content-type: text/html; charset=utf-8
content-length: 1256
cache-control: public, max-age=3600
etag: "33a64df5"
set-cookie: session=abc123; Secure; HttpOnly; SameSite=Lax
<!doctype html>...Headers worth knowing
| Header | What it does |
|---|---|
Content-Type | Format of the body, such as text/html or application/json |
Content-Length | Size of the body in bytes |
Location | Where to go next, used with 3xx and 201 |
Cache-Control | How long and by whom the response may be cached |
ETag | A version tag so clients can ask "has it changed?" |
Authorization | Credentials sent by the client |
Retry-After | How long to wait after a 429 or 503 |
User-Agent | Which client is making the request |
Caching in one minute
Cache-Control: max-age=3600lets caches reuse the response for an hour.Cache-Control: no-storeforbids storing it, for private data.- With an
ETag, a client can sendIf-None-Matchand the server answers304 Not Modifiedwith no body when nothing changed.
Inspect headers
curl -I https://example.comTest yourself
Answer all the questions, then check them. Finish with every answer right to mark the lesson as done.