HTTP Method
- In Turkish
- HTTP Metodu
In short
An HTTP method is the verb in an HTTP request, such as GET, POST, PUT, PATCH or DELETE, that tells the server what action to perform on the requested resource.
What are HTTP methods?
Every HTTP request starts with a method, a short word that states the client's intent, followed by the URL of a resource. GET /users/42 asks to read a user, while DELETE /users/42 asks to remove it. The method lets servers, caches, proxies, and browsers understand what a request will do without looking at its contents.
The five methods you'll use most are GET, which retrieves data and must not change anything; POST, which submits data to create a resource or trigger an action; PUT, which replaces a resource entirely with the data sent; PATCH, which applies a partial update; and DELETE, which removes a resource. Less visible ones include HEAD, which works like GET but returns only the headers, and OPTIONS, which asks what a server allows and is sent by browsers as a CORS preflight request. In REST APIs, these methods line up with the CRUD operations.
Methods are classified by two properties. A safe method (GET, HEAD, OPTIONS) doesn't change server state, which is why browsers may prefetch links and caches may store the responses. An idempotent method (the safe ones plus PUT and DELETE) has the same effect whether it is sent once or several times, so a client can retry it after a timeout, while POST and PATCH are not guaranteed to be idempotent and can create duplicates when retried. Think of the method as the verb of a sentence and the URL as its object: 'get this user', 'delete that order'.
HTTP methods are sometimes confused with HTTP status codes. The method is chosen by the client in the request, while a status code such as 200 or 404 is chosen by the server in the response. A common mistake is using GET for actions that change data, like GET /delete-account, which crawlers, link previews, or prefetching can trigger by accident. Data in a GET request also travels in the URL's query string, where it gets logged and cached, so sensitive data belongs in the body of a POST.
Key takeaways
- The method is the verb of an HTTP request, such as
GET,POST,PUT,PATCH, orDELETE. GETreads,POSTcreates or triggers actions,PUTreplaces,PATCHpartially updates, andDELETEremoves.- Safe methods don't change server state; idempotent methods can be repeated safely.
OPTIONSis used for CORS preflight requests, andHEADfetches only headers.- Never use
GETfor actions that change data.
Example
# Read a resource
curl https://api.example.com/tasks/7
# Create a resource (the server usually replies 201 Created)
curl -X POST https://api.example.com/tasks \
-H "Content-Type: application/json" -d '{"title": "Write report"}'
# Partially update it, then delete it
curl -X PATCH https://api.example.com/tasks/7 \
-H "Content-Type: application/json" -d '{"done": true}'
curl -X DELETE https://api.example.com/tasks/7
# Ask only for the headers (a HEAD request)
curl -I https://api.example.com/tasks/7Readers ask
How many HTTP methods are there?
The core HTTP standard, RFC 9110, defines eight: GET, HEAD, POST, PUT, DELETE, CONNECT, OPTIONS, and TRACE, and PATCH is defined in a separate RFC. Most APIs use only five of them.
Can a GET request have a body?
The HTTP standard gives a body in a GET request no defined meaning, and many servers, proxies, and libraries ignore or reject it, so put GET parameters in the query string. For complex read queries, APIs often use POST, and a new QUERY method has been proposed for safe requests that need a body.
Are HTTP methods case-sensitive?
Yes. Method names are case-sensitive, and the standard ones are always written in uppercase, such as GET and POST.
See also
- HTTPWeb Development, p. 19HTTP is the protocol that browsers, apps, and servers use to exchange web pages and data through a simple cycle of requests and responses.
- REST APIBackend & APIs, p. 38A REST API is a web API that exposes data as resources identified by URLs and lets clients read or change them using standard HTTP methods.
- IdempotencyBackend & APIs, p. 24Idempotency is the property of an operation that produces the same result whether it runs once or many times, so accidentally repeating a request is safe.
- CRUDBackend & APIs, p. 10CRUD stands for create, read, update and delete, the four basic operations for working with stored data in databases, APIs and most business applications.
- HTTP Status CodeWeb Development, p. 21An HTTP status code is a three-digit number a server sends with every response to tell the client whether the request succeeded, failed, or needs more action.
- CORSWeb Development, p. 8CORS is a browser security mechanism that lets a server declare which other websites may read its responses when they make requests from JavaScript.
- HTTP HeaderWeb Development, p. 20An HTTP header is a name-and-value line sent with an HTTP request or response, carrying details such as the content type, caching rules or credentials.
Spotted a mistake or something missing on this page?Suggest an edit