Skip to main content
PacketMentor logo
Open menu
← All topics
Automation & Programmability Foundational

HTTP Essentials: Methods, Status Codes, Headers, Body

The HTTP you need before touching any REST API: four methods (GET POST PUT DELETE), five status code families (1xx 2xx 3xx 4xx 5xx), request/response headers, bodies. Each explained in plain English with a curl lab.

Quick summary
  • HTTP is a question-answer protocol. Client asks (request), server answers (response). Each has: a method/status, headers, and an optional body.
  • Methods you need: GET (read), POST (create or submit), PUT (replace), PATCH (partial update), DELETE (remove).
  • Status codes group by first digit: 2xx = success, 3xx = redirect, 4xx = you messed up, 5xx = the server messed up.

Mental model

HTTP is how your browser, your Python script, and curl all talk to web servers. One side asks (a request); the other side answers (a response). Each side has three parts:

  • A first line (method + URL for requests; status code + reason for responses).
  • A set of headers (metadata: content type, auth, caching).
  • An optional body (JSON, HTML, bytes).

Cisco objectives 2.4 and 2.6 test your ability to read HTTP responses: understand status codes, pick information out of headers, parse the body. Objective 2.1 asks you to construct requests. This topic covers everything you need.

Methods

MethodPurposeIdempotent?Body on request?
GETRead a resourceYesRare
POSTCreate a resource or submit dataNoUsually
PUTReplace a resource entirelyYesYes
PATCHPartially update a resourceNo (usually)Yes
DELETERemove a resourceYesRare

Idempotent = running the same request twice has the same end state as running it once. GET and DELETE and PUT are idempotent. POST is not (two POSTs usually create two resources).

Cisco objective 2.1 asks you to pick the right method given a verb in English:

  • “List all devices” → GET
  • “Add a device” → POST
  • “Replace this device’s full config” → PUT
  • “Change the hostname of this device” → PATCH
  • “Delete this device” → DELETE

Status codes

Three digits. First digit is the family.

FamilyMeaningExamples
1xxInformational (rare in network APIs)100 Continue, 101 Switching Protocols
2xxSuccess200 OK, 201 Created, 204 No Content
3xxRedirect; follow the Location header301 Moved Permanently, 302 Found, 304 Not Modified
4xxClient error — fix your request400 Bad Request, 401 Unauthorized, 403 Forbidden, 404 Not Found, 405 Method Not Allowed, 409 Conflict, 429 Too Many Requests
5xxServer error — not your fault, retry later500 Internal Server Error, 502 Bad Gateway, 503 Service Unavailable

Memorise these common ones for the exam:

  • 200 OK — your GET worked. Payload is in the body.
  • 201 Created — your POST worked and made a new resource. Location header has its URL.
  • 204 No Content — your DELETE worked. No body.
  • 400 Bad Request — your JSON is malformed or missing a field. Read the error body.
  • 401 Unauthorized — you forgot or sent wrong auth.
  • 403 Forbidden — auth was fine but you lack permission.
  • 404 Not Found — the URL does not match any resource.
  • 409 Conflict — your change clashes with current state (e.g., VLAN already exists).
  • 429 Too Many Requests — rate limited. Back off per Retry-After header.
  • 500 Internal Server Error — the server crashed. Not your fault.

Objective 2.4 asks you to explain status codes; 2.5 asks you to troubleshoot given one. The pattern is always:

  1. First digit? 4xx = me. 5xx = them. 2xx = all good.
  2. Specific code? Match to the table above. Read the body for details.

Request shape

POST /devices HTTP/1.1
Host: api.example.com
Authorization: Bearer eyJhbGci...
Content-Type: application/json
Content-Length: 42

{"name": "sw3", "ip": "10.0.0.3"}

Line 1 — method, path, protocol. Lines 2 to 5 — headers. One per line, Name: value. Blank line — separator. Rest — body (optional). Length matches Content-Length.

Response shape

HTTP/1.1 201 Created
Content-Type: application/json
Location: /devices/42
Content-Length: 29

{"id": 42, "created": true}

Same shape, status line instead of request line. Location header points at the new resource (because this was a POST that created something).

Headers that matter for CCNA Automation

HeaderDirectionWhat it means
Content-TypeBothFormat of the body: application/json, application/xml, text/html
AcceptRequestFormats you want back. Server picks one and sets Content-Type accordingly
AuthorizationRequestCredentials: Basic ..., Bearer ...
User-AgentRequestIdentifies your client (curl, Python requests, browser)
Content-LengthBothByte length of the body
LocationResponseURL of the newly-created or redirected-to resource
Retry-AfterResponseSeconds to wait before retrying (returned with 429 and 503)
WWW-AuthenticateResponseAuth scheme the server expects (returned with 401)

Request body

Almost always JSON for modern APIs. For an older or SOAP-style API, XML. Form-encoded (application/x-www-form-urlencoded) still shows up for HTML form submissions.

For CCNA Automation, you will see JSON bodies in nearly every example.

Hands-on lab · 6 minute walkthrough

Hit a real-looking REST API with curl

12 scripted steps. GET a 200. See a 404. Read response headers with -i. POST a device with a JSON body. Watch 401 vs 200 as you add an Authorization header.

Open the lab →
http-essentials · lab
you@laptop:~$ curl https://api.example.com/devices
{"devices":[{"name":"sw1","ip":"10.0.0.1"},...]}
you@laptop:~$ curl -i https://api.example.com/status/200
HTTP/1.1 200 OK
you@laptop:~$

FAQ

What is the difference between PUT and PATCH? PUT replaces the whole resource; the body must contain every field (missing fields are cleared). PATCH applies a delta; only the fields you include change. PATCH is newer and most modern APIs prefer it.

Why is my browser only using GET and POST? HTML forms only support GET and POST. The others are available to JavaScript (fetch), curl, Python requests, and other HTTP clients.

What is an “idempotent” method really? Running the request N times leaves the server in the same final state as running it once. Important when you retry on timeouts: safe for GET/PUT/DELETE, dangerous for POST.

Does HTTPS change any of this? No. HTTPS is HTTP wrapped in TLS. Methods, status codes, headers, body are identical; everything between client and server is encrypted.

What is HTTP/2 or HTTP/3? Do I need to know them for 200-901? No. The exam targets the semantic layer (methods, codes, headers). The transport (1.1 vs 2 vs 3 vs over QUIC) does not change the exam content.

Master this on a real network

Want this drilled into reflex?

1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA Automation® exam blueprint. Free first session. No card on file until you decide.

Claim my free session →

Get the free CCNA 12-week roadmap

You're already reading up on HTTP Essentials: Methods, Status Codes, Headers, Body. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where HTTP Essentials: Methods, Status Codes, Headers, Body fits. A written personal reply, not an autoresponder. Expect it within one business day.

Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.