Resta saysStatus codes summarize the result: 2xx success, 3xx redirect, 4xx client error, 5xx server error.
The first digit tells the story: 2xx worked (200 OK, 201 Created, 204 No Content); 3xx redirect (301, 304 Not Modified); 4xx the client erred (400 Bad Request, 401 Unauthorized, 403 Forbidden, 404 Not Found, 429 Too Many); 5xx the server erred (500, 503). Use the right code so clients can react correctly.
Power-ups you unlock
2xx success · 3xx redirect
4xx client error · 5xx server error
401 (who are you) vs 403 (not allowed)
429 = rate limited
The 401 Bandit attacks — common mistakes
Returning 200 with an error body
Confusing 401 (auth) with 403 (permission)
Using 500 for client mistakes
Boss battlePick the correct status for: created a record, bad input, not logged in, server crash.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>201 Created · made a record
400 Bad Request · invalid input
401 Unauthorized · not logged in
500 Server Error · server crashed</pre></body></html>