Sitelet https://funapi.dev/status/203

HTTP 203 Non-Authoritative Information

The request succeeded, but the body was modified by a transforming proxy between you and the origin server — it is not exactly what the origin sent.

Defined in RFC 9110 §15.3.4 — 203 Non-Authoritative Information · MDN reference

Where you meet HTTP 203 in production

Content-rewriting proxies and some corporate gateways that compress images, strip headers or inject markup. Origin servers almost never send it themselves.

Why you would test it

Rarely produced on purpose, which is why clients that whitelist "200" as the only success break on it. Check your success test is a range, not a single value.

What your client should do about a 203

Treat it as a success — it is one — and remember the representation may differ from the origin's: a checksum or signature over the body may no longer verify, and cached validators may not match.

203 versus the codes it gets confused with

Endpoints that return 203

1 endpoint in this playground answers with 203. Every one is free, needs no signup, and can be called from the browser or with curl.

Questions about HTTP 203

Should my API return 203?
Almost never. It describes what an intermediary did, so it belongs to proxies, not to the application behind them.
Is 203 cacheable?
Yes, by default — it is one of the status codes HTTP lets a cache store without explicit freshness information.

Other success codes

All HTTP status codes · All 39 mock REST APIs · Getting started guide

Last updated