Skip to content

HTTP Versions Explained

Side-by-side reference for HTTP/1.0, HTTP/1.1, HTTP/2, and HTTP/3: transport, connection model, header compression, key features, and adoption notes.

The four HTTP versions compared on how each moves bytes: transport, connection model, header compression, and the features each added. Read one group top to bottom for a single version, or compare the same aspect across all four groups. Use it to debug protocol negotiation, plan an Alt-Svc upgrade, or answer which layer fixed head-of-line blocking.

Reference table · 24 entries
24 of 24 rows
HTTP/1.0
TransportTCPOne plain-text TCP connection, port 80 by default. The spec has no encryption; HTTPS only arrived later as a separate scheme over SSL.
ConnectionsOne request per connectionThe server closes the connection after each response, so every request pays the TCP handshake and slow-start cost again. Keep-alive existed only as a non-standard extension.
Header compressionNoneHeaders travel as plain text on every request, with no shared state between client and server.
Key featuresGET, POST, HEADSimple request-response with MIME-style headers, basic status codes, and the Expires header for caching.
SecurityNone in the specNo authentication or encryption in the protocol itself. Netscape SSL could wrap it in practice, which is where https began.
AdoptionLegacy onlyDefined in RFC 1945 (1996) and superseded by HTTP/1.1 a year later. Servers and proxies still answer 1.0 requests for compatibility, and curl sends 1.1 by default.
HTTP/1.1
TransportTCPPort 80 by default, port 443 when wrapped in TLS. The connection stays plain text unless the https scheme is used.
ConnectionsPersistent (keep-alive)Connections stay open and serve many requests in sequence. Pipelining was specified but suffered head-of-line blocking and was never widely enabled.
Header compressionNoneEvery request repeats all headers in plain text, including cookies, so header overhead grows with every page asset.
Key featuresHost required, chunked encodingThe Host header enables virtual hosting on one IP. Chunked transfer streams bodies of unknown length, and new methods (PUT, DELETE, OPTIONS, CONNECT) plus cache validators (ETag, If-None-Match) arrive.
SecurityTLS via HTTPSTLS wraps HTTP on port 443. There is no in-protocol upgrade, so the URL scheme decides; plain http stays readable on the wire.
AdoptionUniversal baselineEvery client, server, proxy, and CDN speaks it. It remains the fallback when HTTP/2 or HTTP/3 negotiation fails, and the target of API shims.
HTTP/2
TransportTCP + TLSOne TCP connection, almost always TLS on port 443 negotiated as h2 via ALPN. The cleartext h2c mode exists in RFC 9113 but browsers never shipped it.
ConnectionsMultiplexed streamsMany concurrent requests share one connection as parallel streams, ending HTTP-level request queuing. A lost TCP packet still stalls every stream, because TCP delivers in order.
Header compressionHPACKStatic and dynamic Huffman tables compress repeated headers, so cookies and user agents shrink sharply between requests.
Key featuresBinary framing, server pushA binary framing layer replaces the text protocol and adds per-stream priorities and flow control. Server push let servers send resources early, but browsers deprecated and removed it (Chrome 106).
SecurityTLS 1.2+ with ALPNThe h2 ALPN identifier selects the protocol during the TLS handshake. TLS is required in practice by every browser.
AdoptionDefault for HTTPSCarries the majority of HTTPS requests and is supported by every modern browser and CDN. Still the workhorse that HTTP/3 endpoints fall back to.
HTTP/3
TransportQUIC over UDPRuns on QUIC, a UDP transport on port 443 with TLS 1.3 built into the handshake. TCP-only firewall rules block it.
ConnectionsMultiplexed, no TCP HOL blockingIndependent QUIC streams deliver in parallel, so a lost packet stalls only its own stream. Connection IDs let the connection migrate across IP changes, such as Wi-Fi to cellular.
Header compressionQPACKHPACK reworked for QUIC; encode hints let compression instructions ride separately so decompression never re-blocks a stream.
Key features0-RTT, connection migration0-RTT resumption sends request data on the first flight of a reconnect, at the cost of replay risk for non-idempotent requests. The Alt-Svc header advertises the h3 endpoint to clients on older versions.
SecurityTLS 1.3 mandatoryEncryption is integral to QUIC; there is no cleartext HTTP/3, and the transport handshake and the crypto handshake are one.
AdoptionRising, CDN-ledAll major browsers support it and roughly a third of web requests already ride it through CDNs. Both ends need UDP 443 open, which some enterprise networks still block.