HTTP
Hypertext Transfer Protocol
In short
HTTP is the protocol that browsers, apps, and servers use to exchange web pages and data through a simple cycle of requests and responses.
What is HTTP?
HTTP defines how a client, such as a browser or mobile app, asks a server for something and how the server replies. Every exchange is a request followed by a response, and each message is made of a start line, headers that carry metadata, and an optional body with the actual content.
A request names a method that describes the intended action, such as GET to read data, POST to create it, PUT or PATCH to update it, and DELETE to remove it. The response includes a status code that summarizes the result: 200 means success, 404 means not found, and 500 means the server hit an error.
HTTP is stateless, meaning each request stands alone and the server does not automatically remember earlier ones. Cookies and tokens are layered on top to keep users logged in. The protocol has evolved from HTTP/1.1 to HTTP/2 and HTTP/3, which move data more efficiently but keep the same methods, headers, and status codes.
HTTP is often confused with HTTPS. HTTPS is the same protocol sent through an encrypted TLS connection, so outsiders cannot read or tamper with the traffic; plain HTTP sends everything as readable text and should not be used for real websites.
At a glance
Key takeaways
- HTTP works as a series of requests and responses.
- Methods like
GETandPOSTdescribe the requested action. - Status codes like
200and404summarize the result. - HTTP is stateless; cookies and tokens add memory between requests.
- HTTPS is HTTP over an encrypted connection.
Example
# Request sent by the client
GET /users/42 HTTP/1.1
Host: api.example.com
Accept: application/json
# Response sent back by the server
HTTP/1.1 200 OK
Content-Type: application/json
{"id": 42, "name": "Ada"}Readers ask
What is the difference between HTTP and HTTPS?
HTTPS is HTTP sent over an encrypted TLS connection. It protects data from being read or modified in transit and proves to the browser that it is talking to the real website.
What does it mean that HTTP is stateless?
It means the server treats every request independently and does not remember earlier requests on its own. Applications use cookies, sessions, or tokens to recognize returning users.
What is the difference between GET and POST?
GET asks the server to return data and should not change anything, while POST sends data in the request body to create something or trigger an action.
Often compared
See also
- HTTPSSecurity, p. 17HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
- REST APIBackend & APIs, p. 38A REST API is a web API that exposes data as resources identified by URLs and lets clients read or change them using standard HTTP methods.
- APIBackend & APIs, p. 2An API is a set of rules that lets one piece of software request data or actions from another in a predictable, documented way.
- CookieWeb Development, p. 6A cookie is a small piece of data a website asks the browser to store and send back with later requests, often used to keep users logged in.
- CORSWeb Development, p. 8CORS is a browser security mechanism that lets a server declare which other websites may read its responses when they make requests from JavaScript.
- EndpointBackend & APIs, p. 12An endpoint is a specific URL, combined with an HTTP method, where an API receives requests and returns responses for one particular resource or action.
- HTTP/2Networking, p. 9HTTP/2 is the second major version of HTTP, sending many requests and responses at once over one connection in a compact binary format so pages load faster.
- HTTP HeaderWeb Development, p. 20An HTTP header is a name-and-value line sent with an HTTP request or response, carrying details such as the content type, caching rules or credentials.
Sources
Spotted a mistake or something missing on this page?Suggest an edit