Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An HTTP GET request asks a server to transfer the current selected representation of a target resource. In plain language, a browser sends GET when it needs a web page, image, stylesheet, script, or API response. An API client uses GET to retrieve one resource or a filtered collection. The method describes the requested operation; it does not promise that the response will be a particular file type or that the server will return data successfully.

GET is defined by its retrieval semantics, and the details around it matter: query values are visible as part of the URI, responses may be reused by caches, repeating a GET is intended to have the same requested effect, and a request body has no generally defined meaning. Those rules explain when GET is appropriate—and when another method, usually POST, is a better fit.

What does GET mean in HTTP?

RFC 9110 defines GET this way: “The GET method requests transfer of a current selected representation for the target resource.” A representation is the form in which a resource is transferred, such as HTML, JSON, JPEG, or PDF. Content negotiation can let a client express a preference with headers such as Accept, while the server chooses the representation it can provide.

The target resource is identified by the request URI. A GET request therefore asks the server to locate that target and send an appropriate current representation, subject to authorization, routing, content negotiation, and other server rules. A 200 response is common, but redirects, authentication errors, rate limits, not-found responses, and server errors are all valid outcomes of a GET request.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Pearson Computer Networking, 8E
  • brand: Pearson
  • Computer Networking, 8e

An HTTP GET request, piece by piece

Here is a minimal request to an origin server:

GET /products?category=books HTTP/1.1
Host: example.com
Accept: application/json
  • GET is the method.
  • /products is the path.
  • ?category=books is the query string, which supplies a retrieval criterion.
  • HTTP/1.1 identifies the protocol version used for this message.
  • Host identifies the destination host in HTTP/1.1.
  • Accept says that JSON is the client’s preferred response media type.

For an HTTPS request, TLS protects the connection in transit, but the URI still exists at the client and server. Browsers, reverse proxies, analytics systems, and server logs can record it according to their configuration.

What happens when a browser sends GET?

  1. The user enters a URL, follows a link, submits a form configured for GET, or loads a page dependency.
  2. The browser resolves the host name, opens or reuses a connection, and sends a request with the method, target URI, headers, and protocol details.
  3. The server or an intermediary routes the request to an application or static-resource handler.
  4. The server returns a status code, response headers, and, when applicable, a representation in the response body.
  5. The browser may follow redirects, validate a cached response, decode the content, and issue additional GET requests for images, scripts, fonts, and other dependencies.

A page load can therefore involve many GET requests, not just the request for the document URL.

Safe and idempotent: precise meanings

Safe means read-oriented by definition

GET is a safe method. The standard defines safety from the client’s requested perspective: the client is asking for a retrieval operation rather than asking the server to change application state. A server can still record logs, update metrics, refresh a cache, or perform other incidental work. Those side effects do not make the method non-safe under HTTP semantics.

Safety is not a security guarantee. A GET endpoint can expose private data if authorization is missing, and an unsafe application can attach a state-changing action to a GET URL. Such endpoint design is a bug, not a different meaning of the method. Do not use a GET link for an operation such as deleting an account or placing an order.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Idempotent means repeatable intended effect

GET is also idempotent. Repeating the same request is intended to have the same effect on the server as making it once. The responses can differ because the resource changed between requests, authentication expired, or a load-balanced system produced different representations. Idempotence concerns the requested server effect, not byte-for-byte identical responses and not the absence of incidental logging.

Are GET responses cacheable?

Yes, GET responses are defined as cacheable, but that does not mean every response is cached. RFC 9110 says a cache may use a GET response to satisfy later GET or HEAD requests unless the Cache-Control header indicates otherwise. Freshness rules, validators such as ETag and Last-Modified, authorization, intermediary policy, and explicit directives determine whether reuse occurs.

Fresh and revalidated responses

  • A fresh cached response can be returned without contacting the origin.
  • An expired response can be revalidated with a conditional GET, such as If-None-Match. The server may answer 304 Not Modified, allowing the cache to reuse its stored body.
  • Cache-Control: no-store tells compliant caches not to store the response; no-cache generally requires validation before reuse. These directives are not interchangeable.

Caching improves latency and reduces origin work, but private or personalized data needs carefully chosen cache directives. HTTPS prevents network observers from reading the request in transit; it does not override browser history, application logs, proxy policy, or an accidentally shared cache.

Can a GET request have a body?

HTTP messages can contain content, but GET request content has no generally defined semantics. RFC 9110 advises clients not to generate GET content unless the origin server has specifically indicated that it supports a purpose for it. Different servers, frameworks, proxies, and intermediaries may ignore, reject, or mishandle such content.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Put ordinary retrieval criteria in the path or query string, or use headers where that is their defined role. If the operation needs substantial structured input, or if placing values in the URI would disclose sensitive information, use a method designed to carry request content—usually POST—and follow the API’s contract.

GET versus POST

Decision axis GET POST
Typical intent Retrieve a representation of the target resource Ask the target resource to process request content
Where retrieval criteria often go URI path and query Request content may carry data
Safe and idempotent by standard semantics Yes Not guaranteed by the method
Cacheability Defined; use is controlled by cache directives and response conditions Defined in HTTP, but practical support and conditions differ
Privacy consideration URI values can appear in history, logs, analytics, and intermediary records Can carry data in request content when putting it in the URI is inappropriate

This is a semantic comparison, not a blanket security rule. HTTPS, authentication, authorization, logging, browser behavior, and server implementation determine actual confidentiality and access. Never put passwords, access tokens, or unnecessary personal information in a query string merely because GET is convenient.

Query parameters, encoding, and privacy

Query parameters are useful for filters, pagination, sorting, and feature flags: /products?category=books&page=2. Encode values correctly; spaces, ampersands, question marks, and non-ASCII characters have URI-specific rules. A client library’s URL-encoding facility is safer than concatenating untrusted strings.

Because query data is part of the URI, it can be copied into browser history, bookmarks, referrer information, access logs, monitoring systems, and screenshots. A URL does not become private simply because the connection uses HTTPS. For sensitive user-provided information, choose request content or another protocol design when the API permits it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Making GET requests in practical clients

cURL

curl --get 'https://api.example.com/products' 
  --data-urlencode 'category=books' 
  -H 'Accept: application/json'

--data-urlencode adds an encoded query parameter to a GET request. Inspect headers with -i, follow redirects deliberately with -L, and set a connection or total timeout in automation.

JavaScript with fetch

const params = new URLSearchParams({ category: 'books', page: '2' });
const response = await fetch(`https://api.example.com/products?${params}`);
if (!response.ok) throw new Error(`HTTP ${response.status}`);
const data = await response.json();

fetch resolves on HTTP errors, so check response.ok or the status code. Network failures reject the promise; an HTTP 404 does not.

Python with requests

import requests

response = requests.get(
    'https://api.example.com/products',
    params={'category': 'books', 'page': 2},
    timeout=30,
)
response.raise_for_status()
data = response.json()

Passing a params mapping lets the library encode the query string. Always use a finite timeout in scripts and services.

Using GET to create a website screenshot

A screenshot API demonstrates GET clearly: the client sends a URL and options in the query string, while the server returns an image or PDF representation. ScreenshotNeo is a website screenshot API and MCP server for developers. Its base endpoint is https://api.screenshotneo.com/v1/shot.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo documentation for authentication and all options. The same GET can be made in Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)

And in Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`HTTP ${res.status}`);

Or skip the browser setup

For a screenshot workflow, ScreenshotNeo handles the browser work behind one GET call:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
  • Cookie and consent banners, newsletter popups, and chat widgets are removed before the shot; each cleanup step can be turned off.
  • Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status.
  • An MCP server provides take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients.
  • The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots.

It also supports full-page and element captures, device presets, custom CSS and JavaScript, waits, blocking rules, headers and cookies, PDFs, signed links, async jobs, bulk capture, caching, and a usage API. Sign up free for ScreenshotNeo.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting common GET problems

400 Bad Request

The URI or query syntax is invalid, a required parameter is missing, or a value was not encoded. Compare the generated URL with the API documentation and let a client library encode parameters.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

401 or 403

The request lacks valid authentication or the authenticated principal is not allowed to access the resource. Check the required header or credential, expiration, scopes, and target host. Do not put secrets in a query string unless the API explicitly requires it.

404 Not Found

The path or identifier does not map to a resource. Verify the base URL, API version, spelling, and whether a trailing slash has meaning for that service.

405 Method Not Allowed

The resource exists but does not support GET. Use the method listed in the API contract; do not assume that changing the URL will make a POST endpoint readable.

429 Too Many Requests

You have exceeded a rate limit. Honor Retry-After when present, use bounded exponential backoff, and avoid retry storms.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Timeouts or empty responses

Set explicit connect and total timeouts, check DNS and TLS errors separately, inspect status and content type before parsing, and verify whether a proxy or server closed an idle connection. A successful HTTP status does not guarantee that the body is the format your code expected.

Performance, reliability, and design checklist

  • Use GET for retrieval and keep state-changing actions out of GET handlers.
  • Encode query values with a standards-aware library.
  • Send an Accept header when the representation matters, and validate the returned Content-Type.
  • Use cache directives and validators deliberately for public, private, and frequently changing data.
  • Set timeouts, classify HTTP status codes, and retry only failures that are safe for your operation.
  • Keep URLs free of passwords, tokens, and unnecessary personal data.
  • Remember that idempotent does not mean every retry is free: repeated requests can consume quota, bandwidth, or provider charges even when the intended resource effect is unchanged.

Frequently Asked Questions

Is GET encrypted?

Only an HTTPS connection provides transport encryption. Plain HTTP is readable in transit, and HTTPS does not prevent endpoints, logs, browser history, or authorized intermediaries from seeing URI data.

Can I send an API key in a GET query string?

Only when the API explicitly requires it. Query credentials can leak through logs, history, referrers, and monitoring; an authorization header is generally preferable when supported.

Does a GET request always return data?

No. It can return a representation, an empty body, a redirect, or an error status. The status code, headers, and content type must be handled according to the endpoint contract.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why can two identical GET requests return different results?

The resource may have changed, authentication or authorization may differ, caches may revalidate, or the server may select a representation based on headers such as language or media type.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.