HTTP (Hypertext Transfer Protocol) is an application protocol for exchanging messages between clients and servers. It was originally created to transmit hypertext documents. In the OSI model, HTTP is classified as the application layer; in the TCP/IP stack - also to the application layer.
The HTTP protocol works on the principle client-server. The client application generates a request and sends it to the server, after which the server processes the request, generates a response and sends it back to the client. HTTP/1.1 request and response structures are similar: a start line, headers, and an optional message body.
- The starting line of the request consists of the method, path and protocol version:
GET /index.html HTTP/1.1The starting line of the response consists of the protocol version, the response code and the text decryption of the response:HTTP/1.1 200 OK - Headers are a set of key-value pairs, e.g.
Content-Type: text/html; charset=utf-8. The headers contain request/response metadata: user language, authorization, content type, etc. - The request or response body may be missing or contain text or binary data. In HTTP/1.1, it is separated from the headers by a blank line. The usual port for HTTP is 80, for HTTPS is 443. HTTPS is HTTP over TLS: TLS provides encryption, integrity, and server authentication. Today HTTP/1.1, HTTP/2 and HTTP/3 are used. HTTP/2 typically runs on top of TCP, while HTTP/3 runs on top of QUIC, which uses UDP. Features of HTTP/1.1:
- persistent connections are used by default; title
Connection: closereports that the connection should be closed after the response; HTTP/2 innovations: - binary framing: messages are transmitted as sequences of typed frames;
- multiplexing: multiple request and response threads can use the same connection simultaneously;
- header compression: HPACK format is used;
- server push: The protocol allows for additional responses to be sent without a separate request, but browsers no longer support this feature as a practical optimization.
The HTTP/2 standard allows for operation without TLS, but modern browsers practically only use it over TLS.
HTTP methods
Scroll the table horizontally →
| Method | What does | Endpoint example | Safe | Idempotent |
|---|---|---|---|---|
| POST | sends data to the server | /photos | No | No |
| PUT | updates an existing resource, sometimes it can create a new one; you need to pass the full representation of the resource | /photos/id | No | Yes |
| PATCH | makes changes to a specific resource | /photos/id | No | No |
| GET | requests information | /photos, /photos/id | Yes | Yes |
| HEAD | identical to GET in semantics, but the server does not send the response body | /photos, /photos/id | Yes | Yes |
| DELETE | deletes a resource | /photos/id | No | Yes |
| OPTIONS | requests options for interaction with the target resource; often used for CORS preflight requests | /photos | Yes | Yes |
| TRACE | used to test and debug the connection between client and server | /photos | Yes | Yes |
Idempotency — a property of a method where the expected effect of several identical requests is the same as the effect of one request. Responses may differ. PATCH is not required to be idempotent, but a particular PATCH request can be designed to be idempotent.
Example request:
GET /index.html HTTP/1.1
Host: www.example.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:100.0) Gecko/20100101 Firefox/100.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Connection: keep-alive
Upgrade-Insecure-Requests: 1
Example response:
HTTP/1.1 200 OK
Date: Mon, 27 Nov 2023 12:00:00 GMT
Server: Apache/2.4.29 (Unix)
Last-Modified: Wed, 01 Nov 2023 10:00:00 GMT
ETag: "a1f-5c001a1f364d8"
Accept-Ranges: bytes
Content-Type: text/html
<!DOCTYPE html>
<html>
<head>
<title>Example Page</title>
</head>
<body>
<h1>Hello, World!</h1>
<p>This is an example page.</p>
</body>
</html>
Examples of response codes
- 1xx - informational
100 Continue- the request has been accepted and the client can continue sending requests101 Switching Protocols- sent in response to a client request containing the headerUpgrade, and indicates that the server has switched to the agreed protocol- 2xx - successful
200 OK- the request was processed successfully201 Created- the request completed and created one or more resources- 3xx - redirection
304 Not Modified- a conditional GET or HEAD showed that the client's saved representation is still current307 Temporary Redirect- temporary redirect- 4xx - client error
401 Unauthorized- authentication is required to obtain the requested response403 Forbidden- the client does not have permission to access the content404 Not Found- the server cannot find the requested resource- 5xx - server error
500 Internal Server Error- the server encountered a situation it does not know how to handle504 Gateway Timeout- a server acting as a gateway or proxy did not receive a timely response from an upstream server
Primary sources
- RFC 9110: HTTP Semantics
- RFC 9112: HTTP/1.1
- RFC 9113: HTTP/2
- RFC 9114: HTTP/3
- RFC 5789: PATCH Method for HTTP