HTTP
The common language that lets clients and servers talk to each other over the web.
What is it?
For a client and a server to communicate, they both need to agree on a shared format for requests and responses — otherwise it's just noise neither side understands. HTTP (HyperText Transfer Protocol) is that shared language: a set of rules for how a request should be structured, what kinds of requests exist, and how a server should respond.
Explain like I'm 10
HTTP is like the standard format for a letter: a return address, a recipient address, a subject, and a body. Because everyone agrees on that format, any recipient (server) can read a properly formatted letter (request) — and is expected to write back using that same standard format (a response), rather than replying however they feel like.
Examples
A basic HTTP request/response
GET /users/1 HTTP/1.1
Host: api.example.com
// Server responds:
HTTP/1.1 200 OK
Content-Type: application/json
{ "id": 1, "name": "Amara" }GET /users/1 asks for user #1. The server replies with a status code (200 OK means success) and the requested data.
How it works
Every HTTP request has a method (what kind of action, like GET or POST), a path (what resource it's about), and optional headers and a body (extra data). Every response has a status code (like 200 for success or 404 for not found) plus its own headers and body. Both sides just follow this shared structure.
Why does it exist?
Without a shared protocol, every client and server pair would need its own custom way of communicating — nothing on the web would be interoperable. HTTP gives every browser, app, and server a common language, which is why the web works at all.
When to use it
You're using HTTP any time a browser, app, or script talks to a web server — which is most of the time a client-server application communicates at all.
When not to use it
For very high-frequency, low-latency communication — real-time games, some financial trading systems — raw HTTP's overhead can be too much; protocols like WebSockets or dedicated binary protocols fit better there.
Common mistakes
Confusing HTTP status code categories, e.g. thinking all 4xx codes mean 'server error' (they mean client error; 5xx means server error).
Forgetting that HTTP is stateless by default — the server doesn't automatically remember previous requests unless something (like cookies or tokens) carries that state.
Using the wrong method for the action, e.g. using GET for something that changes data on the server.
Practice exercises
- Easy:
List the HTTP methods GET, POST, PUT, and DELETE, and describe what each is typically used for.
- Medium:
Look up what HTTP status codes 200, 301, 404, and 500 mean.
- Hard:
Explain, in your own words, why HTTP being 'stateless' matters for how servers are designed to scale.
Interview questions
What is HTTP?
A protocol (a set of rules) that defines how clients and servers structure requests and responses when communicating over the web.
What does it mean that HTTP is stateless?
Each request is handled independently — the server doesn't automatically remember anything about previous requests from the same client unless extra mechanisms (cookies, tokens, sessions) are used.
What's the difference between GET and POST?
GET requests data without changing anything on the server (and can be cached); POST typically sends data to create or change something on the server.
What does it mean for an HTTP method to be "idempotent"? Which common methods are idempotent?
An idempotent method produces the same end result no matter how many times the identical request is repeated — GET, PUT, DELETE, HEAD, and OPTIONS are idempotent, while POST and PATCH generally are not.
What does it mean for an HTTP method to be "safe", and how is that different from being idempotent?
A safe method doesn't change server state at all (it's read-only, like GET or HEAD); idempotent only requires that repeating the request doesn't change the outcome further — so a method can be idempotent without being safe, like DELETE, which changes state on the first call but not on repeats.
Why is PUT considered idempotent but POST is not?
PUT replaces a resource with the exact representation sent, so sending the same PUT request twice leaves the resource in the same final state; POST typically creates a new resource each time, so repeating it (e.g. resubmitting a form) can create duplicates.
Is DELETE idempotent? Explain with an example.
Yes — deleting the same resource twice leaves it in the same end state (gone) as deleting it once, even though the second request might return a 404 instead of a success status; the result on the server is unchanged, which is what idempotency actually measures.
What's the difference between PATCH and PUT?
PUT is expected to replace an entire resource with the payload sent; PATCH applies a partial update, changing only the fields included in the request while leaving the rest untouched.
What are the five broad categories of HTTP status codes?
1xx (informational, request received and being processed), 2xx (success), 3xx (redirection, further action needed), 4xx (client error), and 5xx (server error).
What's the difference between a 401 and a 403 status code?
401 Unauthorized means the request lacks valid authentication (the client isn't identified, or its credentials are missing/invalid); 403 Forbidden means the client is identified but doesn't have permission to access that resource.
What's the difference between a 404 and a 410 status code?
404 Not Found means the server has no resource at that URL (which could be temporary or permanent); 410 Gone explicitly signals that a resource used to exist there but has been permanently removed, which is a stronger, more specific signal than a plain 404.
What's the difference between a 500 and a 503 status code?
500 Internal Server Error means something went wrong while processing the request on the server itself (an unhandled error, a bug); 503 Service Unavailable means the server is temporarily unable to handle the request (overloaded, down for maintenance) and implies the client can retry later.
What's the difference between a 301 and a 302 redirect?
301 Moved Permanently tells the client (and search engines) the resource has permanently moved to a new URL and future requests should go straight there; 302 Found signals a temporary redirect, meaning the client should keep using the original URL for future requests.
Why does it matter whether a redirect is 301 or 302 for things like caching or search engine indexing?
Browsers and search engines may cache a 301 redirect and transfer the original URL's search ranking to the new one, since it's treated as permanent; a 302 is not cached or trusted the same way, since the original URL is expected to become valid again.
What is the purpose of HTTP headers? Give an example of a request header and a response header.
Headers carry metadata about a request or response separate from its body — e.g. the request header Host tells the server which website the request is for, while the response header Content-Type tells the client how to interpret the body.
What's the difference between the Content-Type and Accept headers?
Content-Type (sent by whichever side includes a body) describes the format of the data actually being sent; Accept (sent by the client) states which response formats the client is willing to receive, letting the server choose accordingly.
At a high level, how does HTTP caching work, and which headers control it?
A response can include caching headers like Cache-Control (how long a response may be reused, and by whom) so that a client or intermediate proxy can reuse a stored copy of a response instead of re-requesting it, until that cache entry expires or is invalidated.
What's the difference between Cache-Control: no-cache and Cache-Control: no-store?
no-cache allows a response to be stored but requires it to be revalidated with the server before each reuse; no-store forbids storing the response at all, which is used for sensitive data that should never be cached anywhere.
What is an ETag, and how does it help avoid re-downloading unchanged data?
It's a token the server generates that identifies a specific version of a resource; the client can send it back in an If-None-Match header on a later request, and if the resource hasn't changed the server replies with a 304 Not Modified and no body, saving bandwidth.
What's the purpose of the If-None-Match header, and how does the server respond to it?
It lets the client say 'only send me the full response if the resource's ETag has changed since I last saw this value' — if the ETag still matches, the server returns 304 Not Modified; if it doesn't, the server returns the current representation with a 200 OK.
Why is HTTP described as stateless, and what mechanisms let applications build state (like being logged in) on top of it?
Each HTTP request is handled independently, with no built-in memory of previous requests; applications add state on top using mechanisms like cookies, sessions, or tokens that are sent with every request to identify the client.
At a conceptual level, what changed between HTTP/1.1 and HTTP/2?
HTTP/1.1 generally needs a separate connection (or queued requests on one) per concurrent request, while HTTP/2 multiplexes many requests and responses over a single connection and compresses headers, reducing overhead and avoiding head-of-line blocking at the connection level.
What problem does HTTP keep-alive solve?
Without it, a new TCP connection would need to be opened and closed for every single request, which is slow; keep-alive reuses one connection for multiple requests/responses, avoiding that repeated setup cost.
Why is the Host header required, even though the request is already being sent to a specific server's IP address?
A single IP address (and port) can serve many different websites (virtual hosting), so the server needs the Host header to know which specific site or application the request is actually meant for.
Why might a client send a HEAD request instead of a GET?
HEAD returns the same headers a GET would, without the body, letting a client check things like whether a resource exists or how large it is, without spending bandwidth downloading the actual content.
What is the OPTIONS method typically used for?
It asks a server what methods and headers are allowed for a given resource, most commonly used automatically by browsers as a CORS "preflight" request before a cross-origin request that isn't considered "simple".
What's the difference between a query parameter and a path parameter in a request URL?
A path parameter identifies a specific resource as part of the URL's structure (e.g. /users/42); a query parameter (e.g. ?sort=name&page=2) modifies how that resource is fetched, like filtering, sorting, or pagination, without changing which resource is being addressed.
Why is it a mistake to use GET for a request that changes data on the server?
GET is expected to be safe and idempotent, so browsers, proxies, and crawlers may prefetch, cache, or repeat GET requests freely — if GET has side effects, those tools can trigger unintended changes without the user or developer expecting it.
What is content negotiation in HTTP?
The process by which a client and server agree on the best representation of a resource to return — e.g. the client's Accept header states preferred formats or languages, and the server picks a matching representation to send back.
Why does the 429 status code exist, and how should a well-behaved client respond to it?
429 Too Many Requests signals that the client has been rate-limited; a well-behaved client should back off and retry later, ideally respecting a Retry-After header if the server includes one, rather than immediately retrying and making the problem worse.