A situation
You type example.com into your browser and press Enter. Less than a second later, a page appears. Behind that page, your browser and a web server had a short, polite conversation. The rules for that conversation are called HTTP.
What it is
HTTP (Hypertext Transfer Protocol) is the protocol browsers use to ask web servers for pages, images and data. It works by request and response: the client (your browser) always asks first, and the server answers. Plain HTTP uses TCP port 80. TCP makes sure every byte arrives, and in the right order.
Before HTTP can start, two other things happen. DNS finds the server's IP address, and TCP opens a connection with its three-way handshake. Each step depends on the one before it.
- 1. 1. DNS lookup. The laptop asks: what is the IP address of example.com? The answer is 203.0.113.10.
- 2. 2. TCP handshake. SYN, SYN-ACK and ACK to port 80 open a reliable connection.
- 3. 3. HTTP request. The browser asks for the page with a GET request.
- 4. 4. HTTP response. The server sends back a status code, some headers and the page itself.
The request and the response
An HTTP message is plain text. The request names a method (what to do) and a path (which resource). The response starts with a status code, a three-digit number that shows the result. Both carry headers: extra lines of information such as the type of content or its size.
HTTP/1.1 keeps the TCP connection open, so later requests reuse it instead of doing a new handshake each time.
Methods
| Method | What it asks the server to do | Everyday example |
|---|---|---|
GET | Send me this resource | Opening a page |
POST | Take this data and process it | Sending a login or contact form |
PUT | Store this data at this path | Uploading or replacing a file through an API |
DELETE | Remove this resource | Deleting an item through an API |
HEAD | Send only the headers, not the body | Checking if a page exists |
Status codes
The first digit tells you the kind of answer:
| Class | Meaning | Common codes |
|---|---|---|
| 2xx | Success | 200 OK |
| 3xx | Go somewhere else | 301 Moved Permanently, 302 Found |
| 4xx | A problem with the request (client error) | 401 Unauthorized, 403 Forbidden, 404 Not Found |
| 5xx | The server failed to handle a valid request | 500 Internal Server Error, 503 Service Unavailable |
Why it works this way
HTTP is stateless: the server does not remember you between requests. Each request carries everything the server needs. This keeps servers simple and lets one server answer millions of clients. When a site does need to remember you, for example to keep you logged in, the browser sends a small piece of data called a cookie with each request to that site.
HTTP also sends everything in clear text, so anyone on the path can read it. That is why almost every site now uses HTTPS, which the next lesson explains. Today, plain HTTP is mostly a first stop that redirects you (with a 301) to the HTTPS version.
Learn more: HTTPS and TLS
How to verify it
On a Windows, macOS or Linux computer, curl can show the response headers. The -I option sends a HEAD request, so only the headers come back.
curl -I http://example.comAsk only for the headers of the page.
Example output, shortened and written for this lesson:
HTTP/1.1 301 Moved Permanently Location: https://example.com/ Content-Type: text/html Content-Length: 162
What to look for: the first line is the status line. The 301 Moved Permanently code and the Location header show that the server is redirecting you to the HTTPS address. Content-Type and Content-Length describe the (short) body the server would send. You can also try the HTTP Headers tool to see the headers of any public site.
Check yourself
You click a link on a website and the browser shows "404 Not Found". What does this tell you?
You fill in a login form and click Sign in. Which method does the browser normally use to send the form?
The DNS lookup for a website fails. Does the browser still send an HTTP request?