
HTTP, or Hypertext Transfer Protocol, is the application-layer protocol used to exchange resources between clients and servers on the Web. It defines the structure of requests and responses used to request and deliver documents, images, data and other content.
HTTP follows a client-server communication model. A browser commonly acts as the client and requests a resource identified by a URL. The server processes the request and returns a response containing a status code, headers and, when appropriate, a body with the requested content.
How HTTP works
Communication begins when the client establishes the required connection and sends an HTTP message. The request includes a method, the target resource, the protocol version and a set of headers. Some requests also contain a body carrying data, such as a submitted form or a JSON representation.
The server interprets the message, applies the relevant logic and produces a response. This response contains a status code, descriptive headers and, where applicable, a body. Headers may specify the content type and length, caching rules, authentication requirements or connection instructions.
HTTP does not require a resource to be a static file. A server may generate a page, query a database, run an application or act as an intermediary. The protocol defines how messages are exchanged, not how the information must be produced internally.
HTTP methods
A method expresses the action that the client wants to perform on a resource. Each method has defined semantics and properties, such as whether it is safe, idempotent or able to carry a body. Common methods include the following:
- GET: Requests a representation of a resource without specifying a modification.
- HEAD: Requests the same headers as GET but does not return the response body.
- POST: Submits data for processing or for creating a subordinate resource.
- PUT: Creates or replaces the representation of the identified resource.
- PATCH: Requests a partial modification of a resource.
- DELETE: Requests removal of the specified association or resource.
- OPTIONS: Queries the communication options available for a target.
The actual result depends on the implementation and the client’s permissions. Using a particular method does not guarantee that the server will accept the operation, so the server must return an appropriate status code.
HTTP status codes
Status codes are three-digit numbers that summarise the result of a request. The first digit identifies the general response category:
- 1xx, informational: The request is continuing or a provisional response has been returned.
- 2xx, successful: The operation was received, understood and processed successfully.
- 3xx, redirection: The client must take another action or use another location.
- 4xx, client error: The request cannot be processed because of its format, permissions or requested resource.
- 5xx, server error: The server could not complete an apparently valid request.
Common examples include 200 OK, 301 Moved Permanently, 404 Not Found and 500 Internal Server Error. The status code provides a short signal, while the headers and body can provide additional information about the result.
HTTP is stateless
HTTP is stateless because each request can be interpreted independently by default. The protocol does not require the server to remember previous requests from the same user automatically. This property simplifies communication, but it does not prevent an application from maintaining a session.
Applications can relate separate requests through a cookie, session identifier, token or information included in the message itself. Therefore, HTTP remains stateless even when an application built on top of it preserves information between interactions.
HTTP versions
HTTP/1.0 established a common foundation for web communication. HTTP/1.1 added persistent connections, more complete caching rules and other improvements. Multiple requests could still block one another or require parallel connections to improve performance.
HTTP/2 introduced binary framing, header compression and multiplexing of several streams over one TCP connection. HTTP/3 retains HTTP semantics but uses QUIC over UDP to reduce certain blocking effects and improve connection establishment and recovery.
The versions do not change the protocol’s fundamental purpose. Methods, status codes and headers continue to express the meaning of messages, while each version changes how those messages are transported more efficiently.
HTTP and HTTPS
HTTPS is HTTP protected with TLS. Encryption helps prevent third parties from reading or modifying the communication in transit, while the certificate allows the client to authenticate the server. HTTPS does not replace HTTP semantics; it protects the channel carrying HTTP messages.
An HTTP URL usually begins with http://, whereas an HTTPS connection uses https://. Current browsers and search engines expect HTTPS on public websites because HTTP transmits information without encryption. Channel protection does not fix application vulnerabilities or guarantee that the content itself is trustworthy.
HTTP also provides mechanisms for caching, content negotiation, authentication, redirection and access control. These capabilities make it an extensible foundation for web pages, APIs and distributed services.
