Contents

Web & Networking › HTTP

HTTP Methods

GET, POST, PUT, PATCH, DELETE and what each one means.

Also known as: HTTP verbs, request methods, GET POST PUT DELETE, HTTP verbs

The method (or “verb”) at the start of a request says what you want to do with the resource at that URL.

MethodMeaningTypical use
GETReadFetch a page or GET /users/42
POSTCreate / perform an actionPOST /orders with the new order in the body
PUTReplacePUT /users/42 with the complete new user
PATCHPartially updatePATCH /users/42 with only the changed fields
DELETERemoveDELETE /orders/917
HEADLike GET, headers onlyCheck existence or size
OPTIONSAsk what’s allowedUsed by browsers for CORS preflight

Two properties that matter

  • Safe: doesn’t change anything on the server. GET and HEAD should be safe. This is why browsers, crawlers and caches feel free to call them freely. Never make a GET that deletes or changes data, because a link prefetcher could trigger it.
  • Idempotent: doing it twice has the same effect as once. GET, PUT and DELETE are idempotent; POST is not, so two identical POSTs can create two orders. That’s why retries need care (see safe and idempotent methods).

Common confusion

  • PUT vs PATCH: PUT sends the whole resource and replaces it; PATCH sends only what changes.
  • POST for everything works but loses information (caching, retry rules). Pick the method that matches the meaning, as in REST.
  • Browsers’ HTML forms only do GET and POST. Other methods come from JavaScript or API clients.

A method doesn’t enforce anything by itself; the server’s code decides what each one does. Following the conventions makes your API predictable to everyone else.