When building web applications or APIs, every request your client sends to a server relies on a specific HTTP method. Whether you're fetching data, submitting a form, or updating a resource, methods like GET, POST, PUT, and DELETE define how that interaction should behave.
Despite their simplicity, HTTP methods are often misunderstood or misused—leading to inefficient APIs, unexpected bugs, or even security issues.
In this guide, we’ll break down the core HTTP methods, explain how they work, highlight the differences between them, and explore when to use each one in real-world scenarios. By the end, you’ll have a clear understanding of how to design and interact with APIs more effectively.
What are the HTTP Methods
HTTP methods form the foundation of communication between clients and servers in modern web architecture. They define the intended action to be performed on a given resource and are a key part of RESTful API design.
If you've ever worked with APIs or web development, you've likely come across terms like GET, POST, PUT, and DELETE. These are known as HTTP methods and they play a crucial role in how data is requested, sent, and modified over the web.
5 Fundamental HTTP Methods
The most common HTTP Methods are GET, POST, PUT, DELETE, and PATCH, which allow the client to read a resource, create it, delete it, or modify it
HTTP GET
The HTTP GET method is used to request data from a specified resource. It should only retrieve data and must not have any side effects (i.e., it should not modify anything on the server). Use this http method only retrieve data and not change anything on the server.
GET is one of the most commonly used HTTP methods and is frequently used when fetching web pages, retrieving API data, and loading information from databases through a backend service.
How does an HTTP GET request work?
Imagine you have an employee management system and want to retrieve employee details.
The flow is:- The client sends a GET request to a URL.
- The server identifies the API endpoint.
- The API retrieves the requested data, often from a database.
- The server returns the data and an HTTP status code, such as 200 OK.
Request Example:
</> http
GET /api/users HTTP/1.1
Host: example.com
Accept: application/json
Response Example:
</> http
HTTP/1.1 200 OK
Content-Type: application/json
</> JSON
[
{
"id": 1,
"name": "Alice"
},
{
"id": 2,
"name": "Bob"
}
]
In this example:
GETspecifies the HTTP method./api/usersidentifies the requested resource.Hostspecifies the server's hostname.Acceptindicates that the client prefers JSON.200 OKindicates that the request succeeded.- The JSON response contains the retrieved user data.
HTTP request with parameter:
</> http
GET /api/products?category=books&limit=10
Here:
- category=books filters products by category.
- limit=10 requests up to 10 results.
| Characteristic | Explanation |
|---|---|
| Primary purpose | Retrieve a resource |
| Request body | Has no generally defined semantics; typically omitted |
| Safe | Yes, it is intended not to change server state |
| Idempotent | Yes, repeating the request has the same intended effect |
| Cacheable | Yes, responses can be cached when caching rules permit |
| Data transmission | Parameters commonly appear in the URL |
| Common status codes | 200 OK, 304 Not Modified, 404 Not Found |
Important: GET requests should not be used to perform actions such as deleting a user or transferring money. Because GET is safe, browsers, crawlers, and caching systems may trigger or repeat such requests in unexpected ways.
Also, URLs can appear in browser history, server logs, and analytics systems. Avoid placing passwords, access tokens, or other sensitive information in query parameters.
HTTP POST
The HTTP POST method is used to send data from a client to a server, usually to create a new resource or perform an operation.
For example, imagine you are developing a restaurant billing application. When a user creates a new bill, the application sends the bill details to the server using an HTTP POST request.
How does HTTP POST work?
For example, imagine you are registering a new user on a website. You enter:- Name: Kailash
- Email: kailash@example.com
- Password: ********
When you click the Register button, the browser sends this information to the server using an HTTP POST request.
The server receives the data, validates it, saves it to a database if appropriate, and sends a response back to the client.
Let's break down.- The client prepares the data.
- The client sends an HTTP POST request to an API endpoint.
- The server receives the request and processes the data.
- The server may save the data in a database or perform another operation.
- The server sends an HTTP response containing a status code and, optionally, a response body.
Request Example:
</> http
POST /api/products HTTP/1.1
Host: example.com
Content-Type: application/json
{
"name": "Kailash"
"email": "kailash@example.com"
"password": "********"
}
Let's understand each part:
POST: HTTP method used to submit data/api/products: API endpoint that receives the requestContent-Type: application/json:Indicates that the request body contains JSON- Request body: Contains the product data
Important: The JSON data is sent in the request body, not as URL query parameters. POST can also carry form data, files, and other supported content types.
| Feature | GET | POST |
|---|---|---|
| Main purpose | Retrieve data | Submit data or trigger processing |
| Data location | Often in URL parameters | Often in request body |
| Typical example | Get product details | Create a product |
| Safe by HTTP definition | Yes | Not necessarily |
| Typically cacheable | Yes | Not by default |
| Idempotent by definition | Yes | Not necessarily |
HTTP PUT
The HTTP PUT method is used to create or completely replace a resource at a specific URL. In REST APIs, PUT is commonly used to update an existing resource, such as updating a user's details, a product, or an employee record.
Imagine you have an employee in your database:- ID: 101
- Name: Kailash
- Email: kailash@example.com
- Department: IT
Now, Rahul changes his email address. You send a PUT request to update the employee's details. The process is:
- The client sends a PUT request to a specific resource URL.
- The request includes the updated data in the request body.
- The API receives the request and validates the data.
- The API updates or replaces the resource.
- The server returns an HTTP response indicating the result.
Request Example:
</> http
POST /api/products HTTP/1.1
Host: example.com
Content-Type: application/json
{
"id": 101,
"name": "Kailash",
"email": "kailash@gmail.com",
"department": "HR"
}
Here:
PUTspecifies the HTTP method./api/employees/101identifies the employee to update.- The JSON body contains the new employee representation.
Important: PUT generally represents a complete replacement of the resource, so omitted fields may be reset or removed depending on the API's implementation. It does not automatically update a database; your server-side code must implement that behavior.
HTTP PATCH
The HTTP PATCH method is used to partially update an existing resource on a server. Let's understand it step by step with a real-world example and ASP.NET Core code.
Suppose you have a user record in a database:</> JSON
{
"id": 101,
"name": "Kailash",
"email": "kailash@example.com",
"city": "Mumbai"
}
Now, you want to change only the user's city from "Mumbai" to "Pune". You don't want to update the name or email. This is where the PATCH method is useful. You send only the information you want to change.
How does HTTP PATCH work?
- The client sends a PATCH request to a specific resource URL.
- The request contains only the fields or operations that need to change.
- The server validates the request and updates the resource.
- The server returns a response indicating the result.
For example, the client sends:
</> http
PATCH /api/users/101 HTTP/1.1
Host: example.com
Content-Type: application/json
Request body:
</> JSON
{
"city": "Pune"
}
The server updates the city while keeping the other fields unchanged.
Difference between HTTP PUT and PATCH
This is one of the most important concepts to understand when learning REST APIs.
| Feature | PUT | PATCH |
|---|---|---|
| Purpose | Replace a resource's representation | Partially modify a resource |
| Data sent | Typically the complete representation | Only the fields or operations to change |
| Update scope | Usually the whole resource | Specific parts of the resource |
| Idempotent | Yes, by HTTP semantics | Depends on the patch operation |
| Example | Replace a user's details | Change only the user's city |
HTTP DELETE
The HTTP DELETE method is used to delete a resource from a server. In a REST API, we typically use it when we want to remove a particular record from a database.
How does the HTTP DELETE method work?
Let's understand it step by step with a real-world example in C# and ASP.NET Core. Imagine you have a student management application that stores student details in a database.
| Id | Name | Age |
|---|---|---|
| 1 | Rahul | 20 |
| 2 | Priya | 22 |
| 3 | Amit | 21 |
Suppose you want to delete Priya's record, which has an ID of 2. Your application sends an HTTP DELETE request to the API. After successful deletion, the database will contain only Rahul and Amit.
Request example</> http
DELETE /api/students/2 HTTP/1.1
Host: localhost:5000
The process usually follows these steps:
- The client sends a DELETE request with the resource ID in the URL.
- The API receives the request and identifies the resource.
- The API checks whether the resource exists and whether the client is authorized to delete it.
- The server deletes the resource if the request is valid.
- The server returns an HTTP status code indicating the result.
Here, DELETE is the HTTP method, and /api/students/2 identifies the student to delete.
Notice that we pass the student ID in the URL rather than sending the complete student object in the request body.
What HTTP status codes can DELETE return?
200 OK: Deletion succeeded; a response body may contain a message or result.204 No Content: Deletion succeeded; no response body is returned.202 Accepted: The deletion request was accepted but has not yet completed.404 Not Found: The requested resource does not exist.401 Unauthorized: Authentication is required or invalid.403 Forbidden: The client does not have permission to delete the resource.
Remember: The HTTP DELETE method requests the removal of a resource identified by its URL. The API performs the operation and returns an appropriate status code to tell the client what happened.
Summary
Understanding HTTP methods is essential for building effective REST APIs and web applications. Each method serves a specific purpose: GET retrieves data, POST submits data, PUT replaces a resource, PATCH partially updates a resource, and DELETE removes a resource.
Choosing the appropriate HTTP method helps developers create APIs that are clear, consistent, and easier to maintain. By understanding these methods, you can design better APIs and improve communication between clients and servers.
Thanks