HTTP Methods
HTTP methods cheat sheet covering GET, POST, PUT, PATCH, DELETE with idempotency rules, request body syntax, and REST API examples.
12 min read
httprestapimethodscrudweb
Other HTTP Sheets
Sign in to mark items as known and track your progress.
Sign inCRUD Methods
GET - Retrieve Resource
javascript
// GET request
fetch('/api/users')
fetch('/api/users/123')
fetch('/api/users?page=2&limit=10')
// Properties
- Safe: Yes
- Idempotent: Yes
- Cacheable: Yes
- Body: No✅ Safe - doesn't modify data
💡 Use query params for filtering
🔍 Cacheable by default
POST - Create Resource
javascript
// POST request
fetch('/api/users', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify(data)
})
// Properties
- Safe: No
- Idempotent: No
- Cacheable: No*
- Body: Yes🆕 Creates new resources
⚠️ Not idempotent - multiple calls create multiple resources
📍 Should return 201 with Location header
PUT - Update/Replace Resource
javascript
// PUT request
fetch('/api/users/123', {
method: 'PUT',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify(completeData)
})
// Properties
- Safe: No
- Idempotent: Yes
- Cacheable: No
- Body: Yes🔄 Replaces entire resource
✅ Idempotent - same request produces same result
📝 Requires complete resource representation
PATCH - Partial Update
javascript
// PATCH request
fetch('/api/users/123', {
method: 'PATCH',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ email: 'new@example.com' })
})
// Properties
- Safe: No
- Idempotent: No*
- Cacheable: No
- Body: Yes🔧 Updates only specified fields
💡 More efficient than PUT for small changes
⚠️ Can be idempotent depending on implementation
DELETE - Remove Resource
javascript
// DELETE request
fetch('/api/users/123', {
method: 'DELETE'
})
// Properties
- Safe: No
- Idempotent: Yes
- Cacheable: No
- Body: Optional🗑️ Removes resources permanently
✅ Idempotent - deleting twice has same effect
💡 Usually returns 204 No Content
Other HTTP Methods
HEAD - Get Headers Only
javascript
// HEAD request
fetch('/api/users', {
method: 'HEAD'
})
// Properties
- Safe: Yes
- Idempotent: Yes
- Cacheable: Yes
- Body: No📋 Same as GET but no body
💡 Useful for checking existence
⚡ Saves bandwidth
OPTIONS - Get Allowed Methods
javascript
// OPTIONS request
fetch('/api/users', {
method: 'OPTIONS'
})
// Properties
- Safe: Yes
- Idempotent: Yes
- Cacheable: No
- Body: Optional🔍 Discovers API capabilities
✈️ Used for CORS preflight
📝 Returns Allow header
CONNECT & TRACE
javascript
// CONNECT - Establish tunnel
CONNECT server.example.com:443 HTTP/1.1
// TRACE - Echo request
TRACE /api/test HTTP/1.1
// Properties
CONNECT: Proxy tunneling
TRACE: Debugging (usually disabled)🚇 CONNECT: For proxy tunneling
🔍 TRACE: Debugging (security risk)
⚠️ Usually disabled in production
Method Properties
Safety & Idempotency
javascript
// Safe Methods (no side effects)
GET, HEAD, OPTIONS, TRACE
// Idempotent Methods (same result)
GET, HEAD, PUT, DELETE, OPTIONS, TRACE
// Neither Safe nor Idempotent
POST, PATCH*🛡️ Safe = no side effects
🔄 Idempotent = same result on retry
💡 Important for caching and retry logic