# Status Codes चुनना — API Design और Versioning

Source: https://www.geekswithgeeks.com/hi/api-design/rr-status-codes

> मानक वर्ग और कुछ सटीक codes को एकरूपता से उपयोग करें।

## वर्ग बताता है ग़लती किसकी है

Status codes पहले अंक से समूहित हैं: **2xx** सफलता, **3xx** redirect या "not modified", **4xx** **client** से ग़लती हुई, **5xx** **server** विफल हुआ। सटीक codes उपयोग करें: `200 OK`, बनाने के बाद `201 Created` (`Location` header के साथ), काम पृष्ठभूमि में जारी रहे तब `202 Accepted`, बिना body की सफलता के लिए `204 No Content`, ग़लत बने input के लिए `400 Bad Request`, `401 Unauthorized` (authenticated नहीं), `403 Forbidden` (authenticated पर अनुमति नहीं), `404 Not Found`, `409 Conflict` (स्थिति का टकराव, जैसे दोहराव), `412 Precondition Failed` (विफल conditional request), `422 Unprocessable Content` (सही बना पर अमान्य डेटा), `429 Too Many Requests` (`Retry-After` के साथ) और `503 Service Unavailable`। Body के भीतर error छिपाकर कभी `200` न लौटाएँ: clients, caches और monitors code पर निर्भर करते हैं।

## क्या हुआ, स्पष्ट बताएँ

Status codes, error bodies और pagination वह जगह हैं जहाँ API या तो भरोसेमंद लगता है या उलझन भरा।

![चार साधन: status, error, page, filter।](assets/figures/api-design/section-2-map.svg) — चित्र 2.1 — Status, error, page और filter।

## घटना से status code, चलाकर

मैंने यह सादा-Python उदाहरण चलाया। छोटा lookup जिसे आप टीम के संदर्भ के रूप में उपयोग कर सकते हैं: created 201, async के लिए स्वीकार 202, deleted 204, validation 422, conflict 409, rate limited 429।

```python
import hmac, hashlib, json, time, bisect

def status_for(event):
    return {"created": 201, "accepted_async": 202, "deleted": 204, "validation": 422, "conflict": 409, "not_found": 404, "unauth": 401, "forbidden": 403, "rate": 429}[event]
print([status_for(e) for e in ("created", "accepted_async", "deleted", "validation", "conflict", "rate")])

```

Output:

```
[201, 202, 204, 422, 409, 429]
```

## 401 बनाम 403

401 का मतलब "मुझे नहीं पता आप कौन हैं" (ग़ायब या ग़लत credentials); 403 का मतलब "मैं जानता हूँ आप कौन हैं और आप यह नहीं कर सकते"। इन्हें मिलाना clients को उलझाता है और bugs छिपाता है।

**Quiz:** User logged in है पर उसे किसी कार्य की अनुमति नहीं। कौन-सा code ठीक है?

- [ ] 401 Unauthorized
- [x] 403 Forbidden
- [ ] 200 OK
- [ ] 500 Internal Server Error

*Answer:* 403 Forbidden. पहचान ज्ञात है पर अनुमति नहीं, जो 403 है।
