httpbin.org

0.9.2
[ Base URL: httpbin.org/ ]

A simple HTTP Request & Response Service.

Echoes what a client actually sends: methods, auth, status codes, request/response inspection, response formats, dynamic data, cookies, images, redirects, anything. Point a client at an endpoint, read the response, assert on it, move on.

# run it locally
$ docker run -p 80:80 kennethreitz/httpbin

# probe the live service
$ curl https://httpbin.org/get

HTTP Methods

5 endpoints
GET /get Returns GET data. Query args and headers echoed back.
curl https://httpbin.org/get
curl -G https://httpbin.org/get -d 'foo=bar' -d 'baz=qux'
POST /post Returns POST data. Form fields and JSON body echoed back.
curl -X POST https://httpbin.org/post -d 'foo=bar'
curl -X POST https://httpbin.org/post -H 'Content-Type: application/json' -d '{"foo":"bar"}'
PUT /put Returns PUT data. Body and headers echoed back.
curl -X PUT https://httpbin.org/put -d 'foo=bar'
PATCH /patch Returns PATCH data. Body and headers echoed back.
curl -X PATCH https://httpbin.org/patch -d 'foo=bar'
DELETE /delete Returns DELETE data. Body and headers echoed back.
curl -X DELETE https://httpbin.org/delete

Auth

6 endpoints
GET /basic-auth/:user/:passwd 401 challenge. Prompts for basic auth; validates credentials.
curl -i https://httpbin.org/basic-auth/user/passwd
curl -i -u user:passwd https://httpbin.org/basic-auth/user/passwd
GET /hidden-basic-auth/:user/:passwd 401 challenge. 404 on success — auth requirement stays hidden.
curl -i -u user:passwd https://httpbin.org/hidden-basic-auth/user/passwd
GET /bearer 401 challenge. Echoes the bearer token when one is sent.
curl -i -H 'Authorization: Bearer sometoken' https://httpbin.org/bearer
GET /digest-auth/:user/:passwd Digest auth challenge. Validates credentials via the handshake.
curl -i --digest -u user:passwd https://httpbin.org/digest-auth/user/passwd
GET /digest-auth/:user/:passwd/:algorithm Digest auth with an explicit algorithm: MD5, SHA-256, SHA-512.
curl -i --digest -u user:passwd https://httpbin.org/digest-auth/user/passwd/SHA-256
GET /digest-auth/:user/:passwd/:qop Digest auth with a specified qop: auth or auth-int.
curl -i --digest -u user:passwd https://httpbin.org/digest-auth/user/passwd/auth

Status codes

1 endpoint
GET /status/:codes Return the given status code, or pick one at random from a list.

Pass one code, or a comma-separated list to draw from. Use it to drive retry, backoff and error-path tests.

curl -i https://httpbin.org/status/429
curl -i https://httpbin.org/status/200,201,418
curl -i https://httpbin.org/status/500

Request inspection

3 endpoints
GET /headers Return the request headers sent to the service.
curl https://httpbin.org/headers
curl -H 'X-Custom: 1' -H 'User-Agent: probe' https://httpbin.org/headers
GET /ip Return the requester's originating IP address.
curl https://httpbin.org/ip
GET /user-agent Return the User-Agent sent with the request.
curl -A 'my-agent/1.0' https://httpbin.org/user-agent

Response inspection

4 endpoints
GET /cache Return 304 when If-Modified-Since or If-None-Match matches.
curl -i https://httpbin.org/cache
curl -i -H 'If-None-Match: "etag"' https://httpbin.org/cache
GET /cache/:n Set Cache-Control on the response for :n seconds.
curl -i https://httpbin.org/cache/60
GET /etag/:etag Assume the resource has the given etag; respond to conditional requests.
curl -i https://httpbin.org/etag/abc
curl -i -H 'If-None-Match: abc' https://httpbin.org/etag/abc
GET /response-headers Return response headers as JSON; set them with query args.
curl -i 'https://httpbin.org/response-headers?X-Test=1&Cache-Control=no-store'

Response formats

9 endpoints
GET /encoding/utf8 Return a UTF-8 encoded payload.
curl https://httpbin.org/encoding/utf8
GET /brotli Return brotli-encoded data. Content-Encoding: br.
curl --compressed https://httpbin.org/brotli
GET /deflate Return deflate-encoded data. Content-Encoding: deflate.
curl --compressed https://httpbin.org/deflate
GET /gzip Return gzip-encoded data. Content-Encoding: gzip.
curl --compressed https://httpbin.org/gzip
GET /html Return a simple HTML page.
curl https://httpbin.org/html
GET /json Return a sample JSON document.
curl https://httpbin.org/json
GET /robots.txt Return some robots.txt rules.
curl https://httpbin.org/robots.txt
GET /xml Return a simple XML document.
curl https://httpbin.org/xml
GET /deny Return a page denied by robots.txt rules.
curl -i https://httpbin.org/deny

Dynamic data

9 endpoints
GET /base64/:value Decode a Base64 encoded string passed as :value.
curl https://httpbin.org/base64/SFRUUEJJTiBpcyBhd2Vzb21l
GET /bytes/:n Return :n random bytes. Binary response body.
curl https://httpbin.org/bytes/256 -o out.bin
GET /delay/:delay Return a response after :delay seconds. Max 10.
curl -w '\ntotal: %{time_total}s\n' https://httpbin.org/delay/2
GET /drip Drip data over a duration. Tune with duration, numbytes, code, delay.
curl -N 'https://httpbin.org/drip?duration=2&numbytes=10&code=200'
GET /links/:n Return an HTML page with :n links chaining down to /links/0.
curl https://httpbin.org/links/10/0
GET /range/:numbytes Stream :numbytes bytes; honors the Range header.
curl -H 'Range: bytes=0-99' https://httpbin.org/range/256 -o part.bin
GET /stream-bytes/:n Stream :n random bytes as the response.
curl -N https://httpbin.org/stream-bytes/256 -o out.bin
GET /stream/:n Stream :n JSON-encapsulated chunks as the response.
curl -N https://httpbin.org/stream/5
GET /uuid Return a UUID4. Fresh value on every request.
curl https://httpbin.org/uuid

Cookies

4 endpoints
GET /cookies Return cookie data as JSON.
curl -b 'session=abc123' https://httpbin.org/cookies
GET /cookies/set Set one or more cookies via query args, then redirect.
curl -i -c jar.txt 'https://httpbin.org/cookies/set?k1=v1&k2=v2'
curl -b jar.txt https://httpbin.org/cookies
GET /cookies/set/:name/:value Set a single cookie :name=:value, then redirect.
curl -i -c jar.txt https://httpbin.org/cookies/set/session/abc123
GET /cookies/delete Delete cookies named in the query args, then redirect.
curl -i -b jar.txt -c jar.txt 'https://httpbin.org/cookies/delete?session'
curl -b jar.txt https://httpbin.org/cookies

Images

5 endpoints
GET /image Return an image selected by the Accept header.
curl -H 'Accept: image/png' https://httpbin.org/image -o img.png
GET /image/png Return a PNG image.
curl https://httpbin.org/image/png -o img.png
file img.png
GET /image/jpeg Return a JPEG image.
curl https://httpbin.org/image/jpeg -o img.jpg
GET /image/webp Return a WEBP image.
curl https://httpbin.org/image/webp -o img.webp
GET /svg Return a SVG image.
curl https://httpbin.org/svg -o img.svg

Redirects

4 endpoints
GET /redirect/:n 302 redirect :n times.
curl -i https://httpbin.org/redirect/2
curl -L https://httpbin.org/redirect/2
GET /redirect-to 302 redirect to the url query arg. Override with status_code.
curl -i 'https://httpbin.org/redirect-to?url=https://httpbin.org/get'
curl -i 'https://httpbin.org/redirect-to?url=https://httpbin.org/post&status_code=307'
GET /relative-redirect/:n 302 redirect :n times via a relative Location.
curl -L https://httpbin.org/relative-redirect/3
GET /absolute-redirect/:n 302 redirect :n times via an absolute Location.
curl -L https://httpbin.org/absolute-redirect/3

Anything

2 endpoints
GET /anything Return anything passed in request data. Accepts any verb.
curl https://httpbin.org/anything/foo/bar?a=1
curl -X PATCH https://httpbin.org/anything -d 'x=1'
OPTIONS /anything/:anything Return anything passed in request data, for any subpath. Any verb.
curl -X OPTIONS -i https://httpbin.org/anything/probe
curl -X POST https://httpbin.org/anything/probe -d 'a=1'

Other Utilities

  • /forms/post — HTML form that POSTs to /post. Use it to exercise form encoding and browser clients.

Ready to send a real request?

Open the Playground