httpbin.org

0.9.2 Live
[ Base URL: httpbin.org/ ]

A simple HTTP Request & Response Service.

Testing an HTTP library can become difficult sometimes. RequestBin is gone, so this service echoes back everything it receives: methods, auth, status codes, request & response inspection, response formats, dynamic data, cookies, images, redirects — anything.

$ docker run -p 80:80 kennethreitz/httpbin
$ curl https://httpbin.org/get

Created by Kenneth Reitz me@kennethreitz.org

HTTP Methods

5 endpoints

Send any verb. The response echoes method, arguments, data and headers.

get /get Returns GET data.

Returns the query string, headers and origin of a GET request.

curl https://httpbin.org/get
post /post Returns POST data.

Accepts form data, JSON or raw bodies and echoes it back.

curl -X POST https://httpbin.org/post
put /put Returns PUT data.

Accepts a body and echoes the full PUT request.

curl -X PUT https://httpbin.org/put
patch /patch Returns PATCH data.

Accepts a body and echoes the full PATCH request.

curl -X PATCH https://httpbin.org/patch
delete /delete Returns DELETE data.

Accepts a body and echoes the full DELETE request.

curl -X DELETE https://httpbin.org/delete

Auth

5 endpoints

Challenge with Basic, Hidden Basic, Digest or Bearer authentication.

get /basic-auth/{user}/{passwd} Challenges Basic Auth.

Prompts for Basic credentials; 200 when they match.

curl -u user:passwd https://httpbin.org/basic-auth/user/passwd
get /hidden-basic-auth/{user}/{passwd} 404s instead of challenging.

Hidden Basic Auth: 200 on success, 404 instead of a challenge.

curl -u user:passwd https://httpbin.org/hidden-basic-auth/user/passwd
get /bearer Challenges Bearer Auth.

Prompts for a bearer token; accepts any non-empty value.

curl -H "Authorization: Bearer token" https://httpbin.org/bearer
get /digest-auth/{user}/{passwd} Challenges Digest Auth (MD5).

Prompts for Digest credentials using the default MD5 algorithm.

curl --digest -u user:passwd https://httpbin.org/digest-auth/user/passwd
get /digest-auth/{user}/{passwd}/{algorithm}/{qop} Digest Auth with chosen algorithm and qop.

Challenges Digest Auth with explicit algorithm (MD5 or SHA-256) and qop (auth or auth-int).

curl --digest -u user:passwd https://httpbin.org/digest-auth/user/passwd/MD5/auth

Status codes

1 endpoint

Return specific status codes — or one at random — to test your client's error handling.

get /status/{codes} Return status code or random status code.

Accepts a single code (429), a list (200,301,404) or a range (200-299). Non-integer codes return a random status.

curl https://httpbin.org/status/429

Request inspection

3 endpoints

Inspect what your client actually sent: headers, origin IP and user agent.

get /headers Returns request headers.

Echoes every header the server received.

curl https://httpbin.org/headers
get /ip Returns Origin IP.

Returns the client IP address as seen by the server.

curl https://httpbin.org/ip
get /user-agent Returns user-agent.

Echoes the User-Agent header of the caller.

curl https://httpbin.org/user-agent

Response inspection

4 endpoints

Control and inspect response headers: caching, validators and custom headers.

get /response-headers Returns response headers from the query string.

Sets response headers from query arguments and echoes them.

curl "https://httpbin.org/response-headers?Content-Type=application/json"
get /cache 200 unless If-Modified-Since or If-None-Match is sent.

Returns 200, or 304 when conditional cache headers match the etag or last-modified value.

curl https://httpbin.org/cache
get /cache/{n} Sets Cache-Control header for n seconds.

Asserts the response carries a cache-control: max-age=n header.

curl https://httpbin.org/cache/60
get /etag/{etag} Assumes the resource has the given etag.

Responds 200, or 304 when If-None-Match matches the etag.

curl -H "If-None-Match: foobar" https://httpbin.org/etag/foobar

Response formats

12 endpoints

Exercise encodings and content types: compressed bodies, JSON, HTML, XML, UTF-8 and robots.

get /encoding/utf8 Returns a UTF-8 encoded body.

Content-Type: text/html; charset=utf-8 with multibyte characters.

curl https://httpbin.org/encoding/utf8
get /gzip Returns gzip-encoded data.

Responds with a gzip-encoded JSON payload.

curl --compressed https://httpbin.org/gzip
get /deflate Returns deflate-encoded data.

Responds with a deflate-encoded JSON payload.

curl https://httpbin.org/deflate
get /brotli Returns brotli-encoded data.

Responds with a brotli-encoded JSON payload.

curl --compressed https://httpbin.org/brotli
get /json Returns some JSON.

A sample JSON document for content-negotiation tests.

curl https://httpbin.org/json
get /html Renders an HTML page.

A simple HTML document with inline markup and headings.

curl https://httpbin.org/html
get /xml Renders an XML document.

A sample XML payload for parsers.

curl https://httpbin.org/xml
get /utf-8 Returns UTF-8 encoded text.

A plaintext body containing UTF-8 multibyte characters.

curl https://httpbin.org/utf-8
get /robots.txt Returns some robots.txt rules.

Disallows half the paths on the service.

curl https://httpbin.org/robots.txt
get /deny Denied by robots.txt.

Returns a plain page saying "YOU SHOULDN'T BE HERE".

curl https://httpbin.org/deny
get /links/{n} Returns page containing n HTML links.

Useful for link extractors and crawlers.

curl https://httpbin.org/links/10
get /link Follows redirects through a link chain.

Query parameters n (total links) and offset (start position) walk the chain.

curl "https://httpbin.org/link?n=10&offset=2"

Dynamic data

8 endpoints

Generate values on the fly: UUIDs, random bytes, delays, drips and streams.

get /uuid Returns a UUID4.

Returns a random UUID in JSON form.

curl https://httpbin.org/uuid
get /delay/{n} Delays the response by n seconds.

Maximum delay is 10 seconds. Great for timeout tests.

curl https://httpbin.org/delay/2
get /drip Drips data over a duration.

Parameters: duration, numbytes, code and delay.

curl "https://httpbin.org/drip?duration=2&numbytes=4"
get /bytes/{n} Returns n random bytes.

Binary application/octet-stream payload of n bytes.

curl https://httpbin.org/bytes/64
get /stream-bytes/{n} Streams n random bytes.

Chunked variant of /bytes/{n} for streaming clients.

curl https://httpbin.org/stream-bytes/64
get /base64/{value} Decodes a Base64 encoded string.

Accepts base64url values and returns the decoded body.

curl https://httpbin.org/base64/SFRUUEJJTiBpcyBhd2Vzb21l
get /stream/{n} Streams n–100 JSON rows.

One JSON object per line, streamed as they are generated.

curl https://httpbin.org/stream/5
get /range/{n} Returns n bytes and honors Range headers.

Responds 206 to ranged requests against the generated bytes.

curl -H "Range: bytes=0-9" https://httpbin.org/range/100

Cookies

3 endpoints

Set and delete cookies, then inspect what your client sent back.

get /cookies Returns cookie data.

Echoes the cookies the client sent.

curl https://httpbin.org/cookies
get /cookies/set Sets one or more cookies.

Pass cookies as query parameters: /cookies/set?name=value.

curl "https://httpbin.org/cookies/set?session=abc123"
get /cookies/delete Deletes cookies by name.

Pass cookie names as query parameters to expire them.

curl "https://httpbin.org/cookies/delete?session"

Images

4 endpoints

Return real image files in the requested format.

get /image/png Returns a PNG.

Content-Type: image/png.

curl -o pixel.png https://httpbin.org/image/png
get /image/jpeg Returns a JPEG.

Content-Type: image/jpeg.

curl -o photo.jpg https://httpbin.org/image/jpeg
get /image/webp Returns a WEBP.

Content-Type: image/webp.

curl -o pic.webp https://httpbin.org/image/webp
get /image/svg Returns an SVG.

Content-Type: image/svg+xml.

curl -o mark.svg https://httpbin.org/image/svg

Redirects

4 endpoints

Generate 302 chains and custom Location headers to stress redirect handling.

get /redirect/{n} 302 redirects n times.

Chains n redirects and finally lands on /get.

curl -L https://httpbin.org/redirect/2
get /relative-redirect/{n} 302 relative redirects n times.

Same chain as /redirect/{n} but with relative Location headers.

curl -L https://httpbin.org/relative-redirect/2
get /absolute-redirect/{n} 302 absolute redirects n times.

Same chain as /redirect/{n} but with absolute Location headers.

curl -L https://httpbin.org/absolute-redirect/2
get /redirect-to 302 redirects to the given URL.

Query parameters: url and optional status code (302 by default).

curl "https://httpbin.org/redirect-to?url=https://httpbin.org/get"

Anything

3 endpoints

Catch-all endpoints that echo whatever your client sends.

get /anything Returns request data for any method.

Accepts any verb and echoes method, headers, arguments and data.

get post put patch delete head options
curl https://httpbin.org/anything
get /anything/{anything} Returns request data under any path.

Same behaviour as /anything for arbitrary sub-paths.

curl https://httpbin.org/anything/deep/path
options /method/{method} Calls the request with the given method.

Forwards to the named verb, e.g. /method/post behaves like /post.

curl -X OPTIONS https://httpbin.org/method/options

Other Utilities

1 endpoint

Beyond request inspection: a plain HTML form you can submit against the service.

post /forms/post HTML form that POSTs to /post.

An HTML form — submit it to see a form-encoded POST echoed back.

curl https://httpbin.org/forms/post

Ready to send a real request?

Build a request in the playground and inspect status, timing, headers and the JSON response.

Open the playground