Skip to content

HTTP

Summary

  • HTTP (Hypertext Transfer Protocol) is an application-layer protocol designed for transferring resources between clients and servers. It is the foundation of the Web and is also widely used by APIs, cloud services, and IoT devices.
  • HTTP uses a request/response model. A client sends an HTTP request to a server, and the server returns an HTTP response containing a status code, headers, and optionally a message body.
  • HTTP is built around resources identified by URIs and operations represented by standardized HTTP methods, such as GET, POST, PUT, PATCH, and DELETE.
  • HTTP uses headers to carry metadata and control information, such as content type, caching, authentication, cookies, and connection behavior.
  • The server communicates the result of a request using an HTTP status code, such as 200 OK, 201 Created, 400 Bad Request, or 404 Not Found.
  • HTTP/1.1 typically uses TCP, while HTTP/2 uses TCP with a binary framing layer. HTTP/3 uses QUIC over UDP, providing stream multiplexing and modern transport features.
  • When confidentiality and authentication are required, HTTP is commonly protected by TLS, forming **HTTP

Status Code

Value Description
100 Continue
101 Switching Protocols
102 Processing
103 Early Hints
104 Upload Resumption Supported (TEMPORARY - registered 2024-11-13, extension registered 2025-09-15, expires 2026-11-13)
105-199 Unassigned
200 OK
201 Created
202 Accepted
203 Non-Authoritative Information
204 No Content
205 Reset Content
206 Partial Content
207 Multi-Status
208 Already Reported
209-225 Unassigned
226 IM Used
227-299 Unassigned
300 Multiple Choices
301 Moved Permanently
302 Found
303 See Other
304 Not Modified
305 Use Proxy
306 (Unused)
307 Temporary Redirect
308 Permanent Redirect
309-399 Unassigned
400 Bad Request
401 Unauthorized
402 Payment Required
403 Forbidden
404 Not Found
405 Method Not Allowed
406 Not Acceptable
407 Proxy Authentication Required
408 Request Timeout
409 Conflict
410 Gone
411 Length Required
412 Precondition Failed
413 Content Too Large
414 URI Too Long
415 Unsupported Media Type
416 Range Not Satisfiable
417 Expectation Failed
418 (Unused)
419-420 Unassigned
421 Misdirected Request
422 Unprocessable Content
423 Locked
424 Failed Dependency
425 Too Early
426 Upgrade Required
427 Unassigned
428 Precondition Required
429 Too Many Requests
430 Unassigned
431 Request Header Fields Too Large
432-450 Unassigned
451 Unavailable For Legal Reasons
452-499 Unassigned
500 Internal Server Error
501 Not Implemented
502 Bad Gateway
503 Service Unavailable
504 Gateway Timeout
505 HTTP Version Not Supported
506 Variant Also Negotiates
507 Insufficient Storage
508 Loop Detected
509 Unassigned
510 Not Extended (OBSOLETED)
511 Network Authentication Required
512-599 Unassigned

Table 1. Hypertext Transfer Protocol (HTTP) Status Code Registry1

Field Names

Field Name Reference Comments
A-IM [RFC 3229: Delta encoding in HTTP]
Accept [RFC 9110, Section 12.5.1: HTTP Semantics]
Accept-Additions [RFC 2324: Hyper Text Coffee Pot Control Protocol (HTCPCP/1.0)]
Accept-CH [RFC 8942, Section 3.1: HTTP Client Hints]
Accept-Charset [RFC 9110, Section 12.5.2: HTTP Semantics]
Accept-Datetime [RFC 7089: HTTP Framework for Time-Based Access to Resource States -- Memento]
Accept-Encoding [RFC 9110, Section 12.5.3: HTTP Semantics]
Accept-Features [RFC 2295: Transparent Content Negotiation in HTTP]
Accept-Language [RFC 9110, Section 12.5.4: HTTP Semantics]
Accept-Patch [RFC 5789: PATCH Method for HTTP]
Accept-Post [Linked Data Platform 1.0]
Accept-Query [RFC 10008, Section 3: The HTTP QUERY Method]
Accept-Ranges [RFC 9110, Section 14.3: HTTP Semantics]
Accept-Signature [RFC 9421, Section 5.1: HTTP Message Signatures]
Access-Control [Access Control for Cross-site Requests]
Access-Control-Allow-Credentials [Fetch]
Access-Control-Allow-Headers [Fetch]
Access-Control-Allow-Methods [Fetch]
Access-Control-Allow-Origin [Fetch]
Access-Control-Expose-Headers [Fetch]
Access-Control-Max-Age [Fetch]
Access-Control-Request-Headers [Fetch]
Access-Control-Request-Method [Fetch]
Activate-Storage-Access [https://privacycg.github.io/storage-access-headers]
Age [RFC 9111, Section 5.1: HTTP Caching]
Allow [RFC 9110, Section 10.2.1: HTTP Semantics]
ALPN [RFC 7639, Section 2: The ALPN HTTP Header Field]
Alt-Svc [RFC 7838: HTTP Alternative Services]
Alt-Used [RFC 7838: HTTP Alternative Services]
Alternates [RFC 2295: Transparent Content Negotiation in HTTP]
AMP-Cache-Transform [AMP-Cache-Transform HTTP request header]
Apply-To-Redirect-Ref [RFC 4437: Web Distributed Authoring and Versioning (WebDAV) Redirect Reference Resources]
Authentication-Control [RFC 8053, Section 4: HTTP Authentication Extensions for Interactive Clients]
Authentication-Info [RFC 9110, Section 11.6.3: HTTP Semantics]
Authorization [RFC 9110, Section 11.6.2: HTTP Semantics]
Available-Dictionary [RFC 9842, Section 2.2: Compression Dictionary Transport]
C-Ext [RFC 2774: An HTTP Extension Framework] [Status change of HTTP experiments to Historic]
C-Man [RFC 2774: An HTTP Extension Framework] [Status change of HTTP experiments to Historic]
C-Opt [RFC 2774: An HTTP Extension Framework] [Status change of HTTP experiments to Historic]
C-PEP [PEP - an Extension Mechanism for HTTP] [Status change of HTTP experiments to Historic]
C-PEP-Info [PEP - an Extension Mechanism for HTTP] [Status change of HTTP experiments to Historic]
Cache-Control [RFC 9111, Section 5.2: HTTP Caching]
Cache-Group-Invalidation [RFC9875: HTTP Cache Groups]
Cache-Groups [RFC9875: HTTP Cache Groups]
Cache-Status [RFC 9211: The Cache-Status HTTP Response Header Field]
Cal-Managed-ID [RFC 8607, Section 5.1: Calendaring Extensions to WebDAV (CalDAV): Managed Attachments]
CalDAV-Timezones [RFC 7809, Section 7.1: Calendaring Extensions to WebDAV (CalDAV): Time Zones by Reference]
Capsule-Protocol [RFC 9297: HTTP Datagrams and the Capsule Protocol]
CDN-Cache-Control [RFC 9213: Targeted HTTP Cache Control] Cache directives targeted at content delivery networks
CDN-Loop [RFC 8586: Loop Detection in Content Delivery Networks (CDNs)]
Cert-Not-After [RFC 8739, Section 3.3: Support for Short-Term, Automatically Renewed (STAR) Certificates in the Automated Certificate Management Environment (ACME)]
Cert-Not-Before [RFC 8739, Section 3.3: Support for Short-Term, Automatically Renewed (STAR) Certificates in the Automated Certificate Management Environment (ACME)]
Clear-Site-Data [Clear Site Data]
Client-Cert [RFC 9440, Section 2: Client-Cert HTTP Header Field]
Client-Cert-Chain [RFC 9440, Section 2: Client-Cert HTTP Header Field]
Close [RFC 9112, Section 9.6: HTTP/1.1] (reserved)
CMCD-Object [CTA][CTA-5004 Common Media Client Data]
CMCD-Request [CTA][CTA-5004 Common Media Client Data]
CMCD-Session [CTA][CTA-5004 Common Media Client Data]
CMCD-Status [CTA][CTA-5004 Common Media Client Data]
CMSD-Dynamic [CTA][CTA-5006 Common Media Server Data (CMSD)]
CMSD-Static [CTA][CTA-5006 Common Media Server Data (CMSD)]
Concealed-Auth-Export [RFC 9729: The Concealed HTTP Authentication Scheme]
Configuration-Context [OSLC Configuration Management Version 1.0. Part 3: Configuration Specification]
Connect-UDP-Bind [RFC-ietf-masque-connect-udp-listen-16: Proxying Bound UDP in HTTP]
Connection [RFC 9110, Section 7.6.1: HTTP Semantics]
Content-Base [RFC 2068: Hypertext Transfer Protocol -- HTTP/1.1] Obsoleted by [RFC 2616: Hypertext Transfer Protocol -- HTTP/1.1]
Content-Digest [RFC 9530, Section 2: Digest Fields]
Content-Disposition [RFC 6266: Use of the Content-Disposition Header Field in the Hypertext Transfer Protocol (HTTP)]
Content-Encoding [RFC 9110, Section 8.4: HTTP Semantics]
Content-ID [The HTTP Distribution and Replication Protocol]
Content-Language [RFC 9110, Section 8.5: HTTP Semantics]
Content-Length [RFC 9110, Section 8.6: HTTP Semantics]
Content-Location [RFC 9110, Section 8.7: HTTP Semantics]
Content-MD5 [RFC 2616, Section 14.15: Hypertext Transfer Protocol -- HTTP/1.1] Obsoleted by [RFC 7231, Appendix B: Hypertext Transfer Protocol (HTTP/1.1): Semantics and Content]
Content-Range [RFC 9110, Section 14.4: HTTP Semantics]
Content-Script-Type [HTML 4.01 Specification]
Content-Security-Policy [Content Security Policy Level 3]
Content-Security-Policy-Report-Only [Content Security Policy Level 3]
Content-Style-Type [HTML 4.01 Specification]
Content-Type [RFC 9110, Section 8.3: HTTP Semantics]
Content-Version [RFC 2068: Hypertext Transfer Protocol -- HTTP/1.1]
Cookie [RFC-ietf-httpbis-rfc6265bis-22, Section 5.8.1: Cookies: HTTP State Management Mechanism]
Cookie2 [RFC 2965: HTTP State Management Mechanism] Obsoleted by [RFC 6265: HTTP State Management Mechanism]
Cross-Origin-Embedder-Policy [HTML]
Cross-Origin-Embedder-Policy-Report-Only [HTML]
Cross-Origin-Opener-Policy [HTML]
Cross-Origin-Opener-Policy-Report-Only [HTML]
Cross-Origin-Resource-Policy [Fetch]
CTA-Common-Access-Token [CTA][Chris_Lemmons]
DASL [RFC 5323: Web Distributed Authoring and Versioning (WebDAV) SEARCH]
Date [RFC 9110, Section 6.6.1: HTTP Semantics]
DAV [RFC 4918: HTTP Extensions for Web Distributed Authoring and Versioning (WebDAV)]
Default-Style [HTML 4.01 Specification]
Delta-Base [RFC 3229: Delta encoding in HTTP]
Deprecation [RFC 9745, Section 2: The Deprecation HTTP Response Header Field]
Depth [RFC 4918: HTTP Extensions for Web Distributed Authoring and Versioning (WebDAV)]
Derived-From [RFC 2068: Hypertext Transfer Protocol -- HTTP/1.1]
Destination [RFC 4918: HTTP Extensions for Web Distributed Authoring and Versioning (WebDAV)]
Detached-JWS [RFC 9635: Grant Negotiation and Authorization Protocol (GNAP)]
Differential-ID [The HTTP Distribution and Replication Protocol]
Dictionary-ID [RFC 9842, Section 2.3: Compression Dictionary Transport]
Digest [RFC 3230: Instance Digests in HTTP] Obsoleted by [RFC 9530, Section 1.3: Digest Fields]
DPoP [RFC 9449: OAuth 2.0 Demonstrating Proof of Possession (DPoP)]
DPoP-Nonce [RFC 9449: OAuth 2.0 Demonstrating Proof of Possession (DPoP)]
Early-Data [RFC 8470: Using Early Data in HTTP]
EDIINT-Features [RFC 6017: Electronic Data Interchange - Internet Integration (EDIINT) Features Header Field]
ETag [RFC 9110, Section 8.8.3: HTTP Semantics]
Expect [RFC 9110, Section 10.1.1: HTTP Semantics]
Expect-CT [RFC 9163: Expect-CT Extension for HTTP] Obsoleted by [IESG]
[HTTPBIS]
Expires [RFC 9111, Section 5.3: HTTP Caching]
Ext [RFC 2774: An HTTP Extension Framework] [Status change of HTTP experiments to Historic]
Forwarded [RFC 7239: Forwarded HTTP Extension]
From [RFC 9110, Section 10.1.2: HTTP Semantics]
GetProfile [Implementation of OPS Over HTTP]
Hobareg [RFC 7486, Section 6.1.1: HTTP Origin-Bound Authentication (HOBA)]
Host [RFC 9110, Section 7.2: HTTP Semantics]
HTTP2-Settings [RFC 7540, Section 3.2.1: Hypertext Transfer Protocol Version 2 (HTTP/2)] Obsolete; see Section 11.1 of [RFC9113]
If [RFC 4918: HTTP Extensions for Web Distributed Authoring and Versioning (WebDAV)]
If-Match [RFC 9110, Section 13.1.1: HTTP Semantics]
If-Modified-Since [RFC 9110, Section 13.1.3: HTTP Semantics]
If-None-Match [RFC 9110, Section 13.1.2: HTTP Semantics]
If-Range [RFC 9110, Section 13.1.5: HTTP Semantics]
If-Schedule-Tag-Match [ RFC 6338: Scheduling Extensions to CalDAV]
If-Unmodified-Since [RFC 9110, Section 13.1.4: HTTP Semantics]
IM [RFC 3229: Delta encoding in HTTP]
Include-Referred-Token-Binding-ID [RFC 8473: Token Binding over HTTP]
Incremental [RFC 10036: Incremental Forwarding of HTTP Messages]
Isolation [OData Version 4.01 Part 1: Protocol][OASIS][Chet_Ensign]
Keep-Alive [RFC 2068: Hypertext Transfer Protocol -- HTTP/1.1]
Label [RFC 3253: Versioning Extensions to WebDAV: (Web Distributed Authoring and Versioning)]
Last-Event-ID [HTML]
Last-Modified [RFC 9110, Section 8.8.2: HTTP Semantics]
Link [RFC 8288: Web Linking]
Link-Template [RFC 9652: The Link-Template HTTP Header Field]
Location [RFC 9110, Section 10.2.2: HTTP Semantics]
Lock-Token [RFC 4918: HTTP Extensions for Web Distributed Authoring and Versioning (WebDAV)]
Man [RFC 2774: An HTTP Extension Framework] [Status change of HTTP experiments to Historic]
Max-Forwards [RFC 9110, Section 7.6.2: HTTP Semantics]
Memento-Datetime [RFC 7089: HTTP Framework for Time-Based Access to Resource States -- Memento]
Meter [RFC 2227: Simple Hit-Metering and Usage-Limiting for HTTP]
Method-Check [Access Control for Cross-site Requests]
Method-Check-Expires [Access Control for Cross-site Requests]
MIME-Version [RFC 9112, Appendix B.1: HTTP/1.1]
Negotiate [RFC 2295: Transparent Content Negotiation in HTTP]
NEL [Network Error Logging]
OData-EntityId [OData Version 4.01 Part 1: Protocol][OASIS][Chet_Ensign]
OData-Isolation [OData Version 4.01 Part 1: Protocol][OASIS][Chet_Ensign]
OData-MaxVersion [OData Version 4.01 Part 1: Protocol][OASIS][Chet_Ensign]
OData-Version [OData Version 4.01 Part 1: Protocol][OASIS][Chet_Ensign]
Opt [RFC 2774: An HTTP Extension Framework] [Status change of HTTP experiments to Historic]
Optional-WWW-Authenticate [RFC 8053, Section 3: HTTP Authentication Extensions for Interactive Clients]
Ordering-Type [RFC 3648: Web Distributed Authoring and Versioning (WebDAV) Ordered Collections Protocol]
Origin [RFC 6454: The Web Origin Concept]
Origin-Agent-Cluster [HTML]
OSCORE [RFC 8613, Section 11.1: Object Security for Constrained RESTful Environments (OSCORE)]
OSLC-Core-Version [OASIS Project Specification 01][OASIS][Chet_Ensign]
Overwrite [RFC 4918: HTTP Extensions for Web Distributed Authoring and Versioning (WebDAV)]
P3P [The Platform for Privacy Preferences 1.0 (P3P1.0) Specification]
PEP [PEP - an Extension Mechanism for HTTP]
PEP-Info [PEP - an Extension Mechanism for HTTP]
Permissions-Policy [Permissions Policy]
PICS-Label [PICS Label Distribution Label Syntax and Communication Protocols]
Ping-From [HTML]
Ping-To [HTML]
Position [RFC 3648: Web Distributed Authoring and Versioning (WebDAV) Ordered Collections Protocol]
Pragma [RFC 9111, Section 5.4: HTTP Caching]
Prefer [RFC 7240: Prefer Header for HTTP]
Preference-Applied [RFC 7240: Prefer Header for HTTP]
Priority [RFC 9218: Extensible Prioritization Scheme for HTTP]
ProfileObject [Implementation of OPS Over HTTP]
Protocol [PICS Label Distribution Label Syntax and Communication Protocols]
Protocol-Info [White Paper: Joint Electronic Payment Initiative]
Protocol-Query [White Paper: Joint Electronic Payment Initiative]
Protocol-Request [PICS Label Distribution Label Syntax and Communication Protocols]
Proxy-Authenticate [RFC 9110, Section 11.7.1: HTTP Semantics]
Proxy-Authentication-Info [RFC 9110, Section 11.7.3: HTTP Semantics]
Proxy-Authorization [RFC 9110, Section 11.7.2: HTTP Semantics]
Proxy-Features [Notification for Proxy Caches]
Proxy-Instruction [Notification for Proxy Caches]
Proxy-Public-Address [RFC-ietf-masque-connect-udp-listen-16: Proxying Bound UDP in HTTP]
Proxy-Status [RFC 9209: The Proxy-Status HTTP Response Header Field]
Public [RFC 2068: Hypertext Transfer Protocol -- HTTP/1.1]
Public-Key-Pins [RFC 7469: Public Key Pinning Extension for HTTP]
Public-Key-Pins-Report-Only [RFC 7469: Public Key Pinning Extension for HTTP]
Range [RFC 9110, Section 14.2: HTTP Semantics]
Redirect-Ref [RFC 4437: Web Distributed Authoring and Versioning (WebDAV) Redirect Reference Resources]
Referer [RFC 9110, Section 10.1.3: HTTP Semantics]
Referer-Root [Access Control for Cross-site Requests]
Referrer-Policy [Referrer Policy] The header name does not share the HTTP Referer header's misspelling.
Refresh [HTML]
Repeatability-Client-ID [Repeatable Requests Version 1.0][OASIS][Chet_Ensign]
Repeatability-First-Sent [Repeatable Requests Version 1.0][OASIS][Chet_Ensign]
Repeatability-Request-ID [Repeatable Requests Version 1.0][OASIS][Chet_Ensign]
Repeatability-Result [Repeatable Requests Version 1.0][OASIS][Chet_Ensign]
Replay-Nonce [RFC 8555, Section 6.5.1: Automatic Certificate Management Environment (ACME)]
Reporting-Endpoints [Reporting API]
Repr-Digest [RFC 9530, Section 3: Digest Fields]
Retry-After [RFC 9110, Section 10.2.3: HTTP Semantics]
Safe [RFC 2310: The Safe Response Header Field] [Status change of HTTP experiments to Historic]
Schedule-Reply [RFC 6638: Scheduling Extensions to CalDAV]
Schedule-Tag [RFC 6338: Scheduling Extensions to CalDAV]
Sec-Fetch-Dest [https://www.w3.org/TR/fetch-metadata/#sec-fetch-dest-header]
Sec-Fetch-Mode [https://www.w3.org/TR/fetch-metadata/#sec-fetch-mode-header]
Sec-Fetch-Site [https://www.w3.org/TR/fetch-metadata/#sec-fetch-site-header]
Sec-Fetch-Storage-Access [https://privacycg.github.io/storage-access-headers]
Sec-Fetch-User [https://www.w3.org/TR/fetch-metadata/#sec-fetch-user-header]
Sec-GPC [Global Privacy Control (GPC)]
Sec-Purpose [Fetch] Intended to replace the (not registered) Purpose and x-moz headers.
Sec-Token-Binding [RFC 8473: Token Binding over HTTP]
Sec-WebSocket-Accept [RFC 6455: The WebSocket Protocol]
Sec-WebSocket-Extensions [RFC 6455: The WebSocket Protocol]
Sec-WebSocket-Key [RFC 6455: The WebSocket Protocol]
Sec-WebSocket-Protocol [RFC 6455: The WebSocket Protocol]
Sec-WebSocket-Version [RFC 6455: The WebSocket Protocol]
Security-Scheme [RFC 2660: The Secure HyperText Transfer Protocol] [Status change of HTTP experiments to Historic]
Server [RFC 9110, Section 10.2.4: HTTP Semantics]
Server-Timing [Server Timing]
Set-Cookie [RFC-ietf-httpbis-rfc6265bis-22, Section 5.8.1: Cookies: HTTP State Management Mechanism]
Set-Cookie2 [RFC 2965: HTTP State Management Mechanism] Obsoleted by [RFC 6265: HTTP State Management Mechanism]
Set-Txn [RFC9967, Section 3: SCIM Profile for Security Event Tokens]
SetProfile [Implementation of OPS Over HTTP]
Signature [RFC 9421, Section 4.2: HTTP Message Signatures]
Signature-Input [RFC 9421, Section 4.1: HTTP Message Signatures]
SLUG [RFC 5023: The Atom Publishing Protocol]
SoapAction [Simple Object Access Protocol (SOAP) 1.1]
Status-URI [RFC 2518: HTTP Extensions for Distributed Authoring -- WEBDAV]
Strict-Transport-Security [RFC 6797: HTTP Strict Transport Security (HSTS)]
Sunset [RFC 8594: The Sunset HTTP Header Field]
Surrogate-Capability [Edge Architecture Specification]
Surrogate-Control [Edge Architecture Specification]
TCN [RFC 2295: Transparent Content Negotiation in HTTP]
TE [RFC 9110, Section 10.1.4: HTTP Semantics]
Timeout [RFC 4918: HTTP Extensions for Web Distributed Authoring and Versioning (WebDAV)]
Timing-Allow-Origin [Resource Timing Level 1]
Topic [RFC 8030, Section 5.4: Generic Event Delivery Using HTTP Push]
Traceparent [Trace Context]
Tracestate [Trace Context]
Trailer [RFC 9110, Section 6.6.2: HTTP Semantics]
Transfer-Encoding [RFC 9112, Section 6.1: HTTP Semantics]
TTL [RFC 8030, Section 5.2: Generic Event Delivery Using HTTP Push]
Unencoded-Digest [RFC-ietf-httpbis-unencoded-digest-05, Section 3: HTTP Unencoded Digest]
Upgrade [RFC 9110, Section 7.8: HTTP Semantics]
Urgency [RFC 8030, Section 5.3: Generic Event Delivery Using HTTP Push]
URI [RFC 2068: Hypertext Transfer Protocol -- HTTP/1.1]
Use-As-Dictionary [RFC 9842, Section 2.1: Compression Dictionary Transport]
User-Agent [RFC 9110, Section 10.1.5: HTTP Semantics]
Variant-Vary [RFC 2295: Transparent Content Negotiation in HTTP]
Vary [RFC 9110, Section 12.5.5: HTTP Semantics]
Via [RFC 9110, Section 7.6.3: HTTP Semantics]
Want-Content-Digest [RFC 9530, Section 4: Digest Fields]
Want-Digest [RFC 3230: Instance Digests in HTTP] Obsoleted by [RFC 9530, Section 1.3: Digest Fields]
Want-Repr-Digest [RFC 9530, Section 4: Digest Fields]
Want-Unencoded-Digest [RFC-ietf-httpbis-unencoded-digest-05, Section 4: HTTP Unencoded Digest]
Warning [RFC 9111, Section 5.5: HTTP Caching]
WWW-Authenticate [RFC 9110, Section 11.6.1: HTTP Semantics]
X-Content-Type-Options [Fetch]
X-Frame-Options [HTML]
* [RFC 9110, Section 12.5.5: HTTP Semantics] (reserved)

Table 2. Hypertext Transfer Protocol (HTTP) Field Name Registry2