Firefox Tomorrow

guide

HTTP resources and specifications

View on MDN ↗

HTTP was first specified in the early 1990s. Designed with extensibility in mind, it has seen numerous additions over the years; this lead to its specification being scattered through numerous specification documents (in the midst of experimental abandoned extensions). This page lists relevant resources about HTTP.

SpecificationTitleStatus
9110HTTP SemanticsInternet Standard
9111HTTP CachingInternet Standard
9112HTTP/1.1Internet Standard
9113HTTP/2Proposed Standard
9114HTTP/3Proposed Standard
5861HTTP Cache-Control Extensions for Stale ContentInformational
8246HTTP Immutable ResponsesProposed Standard
6265HTTP State Management Mechanism Defines CookiesProposed Standard
Draft specCookie PrefixesIETF Draft
Draft specSame-Site CookiesIETF Draft
Draft specDeprecate modification of ‘secure’ cookies from non-secure originsIETF Draft
2145Use and Interpretation of HTTP Version NumbersInformational
6585Additional HTTP Status CodesProposed Standard
7725An HTTP Status Code to Report Legal ObstaclesOn the standard track
2397The “data” URL schemeProposed Standard
3986Uniform Resource Identifier (URI): Generic SyntaxInternet Standard
5988Web Linking Defines the Link headerProposed Standard
Draft specHTTP Client HintsIETF Draft
7578Returning Values from Forms: multipart/form-dataProposed Standard
6266Use of the Content-Disposition Header Field in the Hypertext Transfer Protocol (HTTP)Proposed Standard
2183Communicating Presentation Information in Internet Messages: The Content-Disposition Header Field Only a subset of syntax of the Content-Disposition header can be used in the context of HTTP messages.Proposed Standard
7239Forwarded HTTP ExtensionProposed Standard
6455The WebSocket ProtocolProposed Standard
5246The Transport Layer Security (TLS) Protocol Version 1.2 This specification has been modified by subsequent RFCs, but these modifications have no effect on the HTTP protocol.Proposed Standard
8446The Transport Layer Security (TLS) Protocol Version 1.3 Supersedes TLS 1.2.Proposed Standard
2817Upgrading to TLS Within HTTP/1.1Proposed Standard
7541HPACK: Header Compression for HTTP/2On the standard track
7838HTTP Alternative ServicesOn the standard track
7301Transport Layer Security (TLS) Application-Layer Protocol Negotiation Extension Used to negotiate HTTP/2 at the transport to save an extra request/response round trip.Proposed Standard
6454The Web Origin ConceptProposed Standard
FetchCross-Origin Resource SharingLiving Standard
7034HTTP Header Field X-Frame-OptionsInformational
6797HTTP Strict Transport Security (HSTS)Proposed Standard
Upgrade Insecure RequestsUpgrade Insecure RequestsCandidate Recommendation
Content Security Policy specificationContent Security Policy Level 3Obsolete
Microsoft documentSpecifying legacy document modes* Defines X-UA-CompatibleNote
5689HTTP Extensions for Web Distributed Authoring and Versioning (WebDAV) These extensions of the Web, as well as CardDAV and CalDAV, are out-of-scope for HTTP on the Web. Modern APIs for application are defines using the RESTful pattern nowadays.Proposed Standard
2324Hyper Text Coffee Pot Control Protocol (HTCPCP/1.0)April 1st joke spec
7168The Hyper Text Coffee Pot Control Protocol for Tea Efflux Appliances (HTCPCP-TEA)April 1st joke spec
HTML Living StandardHTML Defines extensions of HTTP for Server-Sent EventsLiving Standard
Reporting APIReport-To headerDraft
Draft specExpect-CT Extension for HTTPIETF Draft
7486HTTP Origin-Bound Auth (HOBA)Experimental
7240Prefer Header for HTTPProposed Standard

See also