HTTP Status Codes Used in API Testing
Problem: Quickly interpret HTTP responses when testing APIs.
Common codes
- 200 OK
- Successful request; inspect body for expected data.
- 201 Created
- Resource created; check Location header and response body.
- 400 Bad Request
- Client-side validation issue — check payload and parameters.
- 401 Unauthorized
- Authentication required or token invalid/expired.
- 403 Forbidden
- Authenticated but not authorized to perform the action.
- 404 Not Found
- Resource does not exist or wrong URL.
- 500 Internal Server Error
- Server-side error — collect logs and request details for debugging.
Practical tips
- When seeing
401, decode the JWT to inspect expiry or scopes using JWT Decoder. - For
400, validate JSON with JSON Formatter.