HTTP/2
- Pronunciation
- aych-tee-tee-pee TOO
In short
HTTP/2 is the second major version of HTTP, sending many requests and responses at once over one connection in a compact binary format so pages load faster.
What is HTTP/2?
With HTTP/1.1, a connection carries one request at a time, so browsers opened up to six connections per site and still waited in line, and developers resorted to tricks such as bundling files and image sprites. HTTP/2, based on Google's experimental SPDY protocol and published as a standard in 2015, removes that bottleneck while keeping the same methods, status codes and headers.
Its key feature is multiplexing. Messages are split into binary frames, each tagged with a stream ID, so dozens of requests and responses can be interleaved over a single TCP connection without waiting for each other. HPACK compresses headers, which repeat on almost every request, and streams can carry priorities so important resources arrive first.
For applications nothing changes at the code level: a fetch call or a server route works the same over either version, and the browser and server negotiate HTTP/2 automatically during the TLS handshake. Browsers only use HTTP/2 over HTTPS, so enabling it usually means enabling TLS on the server or CDN. Server push, an early feature for sending files before they were requested, was little used and has since been dropped by browsers.
A common misconception is that HTTP/2 removes all waiting. It fixes head-of-line blocking at the HTTP level, but everything still runs over one TCP connection, so a single lost packet holds up every stream. HTTP/3 solves this by running over QUIC on UDP, where streams are independent.
Key takeaways
- HTTP/2 was standardized in 2015, based on Google's SPDY.
- Multiplexing sends many requests at once over one connection.
- It uses binary frames and HPACK header compression.
- Browsers use it only over HTTPS; application code doesn't change.
- TCP-level head-of-line blocking remains; HTTP/3 over QUIC fixes it.
Example
# Ask for HTTP/2 and print the protocol that was negotiated
curl -sI --http2 https://example.com -o /dev/null -w '%{http_version}\n'
# 2
# nginx: enable HTTP/2 on the TLS listener
# listen 443 ssl;
# http2 on;Readers ask
What is the difference between HTTP/1.1 and HTTP/2?
HTTP/1.1 is text-based and handles one request at a time per connection. HTTP/2 is binary, compresses headers and multiplexes many requests over a single connection, which reduces latency, especially for pages with many files.
Does HTTP/2 require HTTPS?
The standard allows unencrypted HTTP/2, but all major browsers only support it over TLS, so in practice it requires HTTPS.
Should I still bundle files with HTTP/2?
Less aggressively. Many small files are no longer expensive, so splitting code by page works well, but bundling still helps compression and avoids very deep chains of imports.
See also
- HTTPWeb Development, p. 19HTTP is the protocol that browsers, apps, and servers use to exchange web pages and data through a simple cycle of requests and responses.
- HTTPSSecurity, p. 17HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
- QUICNetworking, p. 24QUIC is a modern transport protocol built on UDP that provides encrypted, reliable, multiplexed connections with fast setup, and it is the foundation of HTTP/3.
- TCPNetworking, p. 30TCP is a core internet protocol that delivers data between two programs reliably and in order, by opening a connection and resending anything that gets lost.
- TLSSecurity, p. 45TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- LatencyNetworking, p. 14Latency is the delay between sending a request and the start of a response, usually measured in milliseconds, and it shapes how responsive an app feels.
Sources
Spotted a mistake or something missing on this page?Suggest an edit