HTTP REFERENCE
Not just what each code means — but when to use it. Status codes, methods, headers, and curl examples for API developers. Because "400 vs 422" shouldn't require a 30-minute research session.
400 vs 422: What's the difference?
400 Bad Request is for syntactically broken requests — invalid JSON, missing Content-Type, malformed URL. The server couldn't parse it.
422 Unprocessable Entity is for semantically invalid data — the JSON is valid, but the values don't make sense (end date before start date, password too short).
Rule: if the parser can read it but the logic rejects it → 422. If it can't even parse → 400.
200 vs 204: When there's no body
200 OK implies there's a response body with content.
204 No Content means the operation succeeded but there's intentionally nothing to return. Use this for DELETE and update operations that don't need to return data.
Returning 200 with an empty body is technically wrong — use 204 instead.
401 vs 403: Auth vs Authz
401 Unauthorized (badly named) means "you need to authenticate first — who are you?" Always include WWW-Authenticate.
403 Forbidden means "I know who you are, but you can't do this." The user is logged in but lacks permission.
If in doubt: unauthenticated = 401, authenticated but unauthorized = 403.