HTTP logoHTTPBEGINNER

HTTP Methods

HTTP methods cheat sheet covering GET, POST, PUT, PATCH, DELETE with idempotency rules, request body syntax, and REST API examples.

12 min read
httprestapimethodscrudweb

Other HTTP Sheets

Sign in to mark items as known and track your progress.

Sign in

CRUD Methods

GET - Retrieve Resource

javascript
// GET request
fetch('/api/users')
fetch('/api/users/123')
fetch('/api/users?page=2&limit=10')

// Properties
- Safe: Yes
- Idempotent: Yes
- Cacheable: Yes
- Body: No
✅ Safe - doesn't modify data
💡 Use query params for filtering
🔍 Cacheable by default

POST - Create Resource

javascript
// POST request
fetch('/api/users', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify(data)
})

// Properties
- Safe: No
- Idempotent: No
- Cacheable: No*
- Body: Yes
🆕 Creates new resources
⚠️ Not idempotent - multiple calls create multiple resources
📍 Should return 201 with Location header

PUT - Update/Replace Resource

javascript
// PUT request
fetch('/api/users/123', {
  method: 'PUT',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify(completeData)
})

// Properties
- Safe: No
- Idempotent: Yes
- Cacheable: No
- Body: Yes
🔄 Replaces entire resource
✅ Idempotent - same request produces same result
📝 Requires complete resource representation

PATCH - Partial Update

javascript
// PATCH request
fetch('/api/users/123', {
  method: 'PATCH',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({ email: 'new@example.com' })
})

// Properties
- Safe: No
- Idempotent: No*
- Cacheable: No
- Body: Yes
🔧 Updates only specified fields
💡 More efficient than PUT for small changes
⚠️ Can be idempotent depending on implementation

DELETE - Remove Resource

javascript
// DELETE request
fetch('/api/users/123', {
  method: 'DELETE'
})

// Properties
- Safe: No
- Idempotent: Yes
- Cacheable: No
- Body: Optional
🗑️ Removes resources permanently
✅ Idempotent - deleting twice has same effect
💡 Usually returns 204 No Content

Other HTTP Methods

HEAD - Get Headers Only

javascript
// HEAD request
fetch('/api/users', {
  method: 'HEAD'
})

// Properties
- Safe: Yes
- Idempotent: Yes
- Cacheable: Yes
- Body: No
📋 Same as GET but no body
💡 Useful for checking existence
⚡ Saves bandwidth

OPTIONS - Get Allowed Methods

javascript
// OPTIONS request
fetch('/api/users', {
  method: 'OPTIONS'
})

// Properties
- Safe: Yes
- Idempotent: Yes
- Cacheable: No
- Body: Optional
🔍 Discovers API capabilities
✈️ Used for CORS preflight
📝 Returns Allow header

CONNECT & TRACE

javascript
// CONNECT - Establish tunnel
CONNECT server.example.com:443 HTTP/1.1

// TRACE - Echo request
TRACE /api/test HTTP/1.1

// Properties
CONNECT: Proxy tunneling
TRACE: Debugging (usually disabled)
🚇 CONNECT: For proxy tunneling
🔍 TRACE: Debugging (security risk)
⚠️ Usually disabled in production

Method Properties

Safety & Idempotency

javascript
// Safe Methods (no side effects)
GET, HEAD, OPTIONS, TRACE

// Idempotent Methods (same result)
GET, HEAD, PUT, DELETE, OPTIONS, TRACE

// Neither Safe nor Idempotent
POST, PATCH*
🛡️ Safe = no side effects
🔄 Idempotent = same result on retry
💡 Important for caching and retry logic

More HTTP Cheat Sheets