| HTTP/1.0 |
|---|
| Transport | TCP | One plain-text TCP connection, port 80 by default. The spec has no encryption; HTTPS only arrived later as a separate scheme over SSL. |
| Connections | One request per connection | The server closes the connection after each response, so every request pays the TCP handshake and slow-start cost again. Keep-alive existed only as a non-standard extension. |
| Header compression | None | Headers travel as plain text on every request, with no shared state between client and server. |
| Key features | GET, POST, HEAD | Simple request-response with MIME-style headers, basic status codes, and the Expires header for caching. |
| Security | None in the spec | No authentication or encryption in the protocol itself. Netscape SSL could wrap it in practice, which is where https began. |
| Adoption | Legacy only | Defined in RFC 1945 (1996) and superseded by HTTP/1.1 a year later. Servers and proxies still answer 1.0 requests for compatibility, and curl sends 1.1 by default. |
| HTTP/1.1 |
|---|
| Transport | TCP | Port 80 by default, port 443 when wrapped in TLS. The connection stays plain text unless the https scheme is used. |
| Connections | Persistent (keep-alive) | Connections stay open and serve many requests in sequence. Pipelining was specified but suffered head-of-line blocking and was never widely enabled. |
| Header compression | None | Every request repeats all headers in plain text, including cookies, so header overhead grows with every page asset. |
| Key features | Host required, chunked encoding | The Host header enables virtual hosting on one IP. Chunked transfer streams bodies of unknown length, and new methods (PUT, DELETE, OPTIONS, CONNECT) plus cache validators (ETag, If-None-Match) arrive. |
| Security | TLS via HTTPS | TLS wraps HTTP on port 443. There is no in-protocol upgrade, so the URL scheme decides; plain http stays readable on the wire. |
| Adoption | Universal baseline | Every client, server, proxy, and CDN speaks it. It remains the fallback when HTTP/2 or HTTP/3 negotiation fails, and the target of API shims. |
| HTTP/2 |
|---|
| Transport | TCP + TLS | One TCP connection, almost always TLS on port 443 negotiated as h2 via ALPN. The cleartext h2c mode exists in RFC 9113 but browsers never shipped it. |
| Connections | Multiplexed streams | Many concurrent requests share one connection as parallel streams, ending HTTP-level request queuing. A lost TCP packet still stalls every stream, because TCP delivers in order. |
| Header compression | HPACK | Static and dynamic Huffman tables compress repeated headers, so cookies and user agents shrink sharply between requests. |
| Key features | Binary framing, server push | A binary framing layer replaces the text protocol and adds per-stream priorities and flow control. Server push let servers send resources early, but browsers deprecated and removed it (Chrome 106). |
| Security | TLS 1.2+ with ALPN | The h2 ALPN identifier selects the protocol during the TLS handshake. TLS is required in practice by every browser. |
| Adoption | Default for HTTPS | Carries the majority of HTTPS requests and is supported by every modern browser and CDN. Still the workhorse that HTTP/3 endpoints fall back to. |
| HTTP/3 |
|---|
| Transport | QUIC over UDP | Runs on QUIC, a UDP transport on port 443 with TLS 1.3 built into the handshake. TCP-only firewall rules block it. |
| Connections | Multiplexed, no TCP HOL blocking | Independent QUIC streams deliver in parallel, so a lost packet stalls only its own stream. Connection IDs let the connection migrate across IP changes, such as Wi-Fi to cellular. |
| Header compression | QPACK | HPACK reworked for QUIC; encode hints let compression instructions ride separately so decompression never re-blocks a stream. |
| Key features | 0-RTT, connection migration | 0-RTT resumption sends request data on the first flight of a reconnect, at the cost of replay risk for non-idempotent requests. The Alt-Svc header advertises the h3 endpoint to clients on older versions. |
| Security | TLS 1.3 mandatory | Encryption is integral to QUIC; there is no cleartext HTTP/3, and the transport handshake and the crypto handshake are one. |
| Adoption | Rising, CDN-led | All major browsers support it and roughly a third of web requests already ride it through CDNs. Both ends need UDP 443 open, which some enterprise networks still block. |