What it means
The default success. One thing worth getting right: a successful request that found nothing is still 200 with an empty list - an empty collection is not a 404. 404 means the *endpoint or resource* does not exist, not that a query matched no rows.
- Class
- 2xx Success
- Defined in
- RFC 9110 §15.3.1
- Cached by default
- Yes, without explicit headers
When you receive a 200
- The request worked, but read the body before trusting it: some APIs return 200 with an error object inside, and the status alone proves nothing there.
- A 200 with an empty list means the query matched nothing. The endpoint exists; it is not a missing resource.
- If you expected a
304from a cached request and keep getting 200, the conditional headers (If-None-Match,ETag) are not round-tripping.
When you send a 200
- Use it for a successful
GET, and for aPOSTorPUTthat returns a result rather than creating something new. - Never wrap a failure in a 200. Clients, retry logic, monitoring and caches all read the status first.
- A search that finds nothing is 200 with an empty array, not
404and not204.
On the wire
HTTP/1.1 200 OK
Content-Type: application/json
Cache-Control: max-age=60
{"items": [], "total": 0}