How it works
Every exchange is a request and a response. The request names a method (GET, POST), a URL and headers (who is asking, which formats they accept, any cookies); the response carries a status code (200, 404), headers and a body, such as HTML, JSON or an image. HTTP itself is stateless: each request stands alone, and cookies or tokens are how a server recognises a returning visitor.
HTTPS wraps the same conversation in TLS encryption, backed by the site's certificate. Browsers label plain HTTP pages 'Not secure', and many features, such as service workers, geolocation and passkeys, work only over HTTPS. Newer versions change how the bytes travel, not what they mean: HTTP/2 sends many requests over one connection, and HTTP/3 runs over QUIC on UDP to cope better with slow or patchy mobile networks.
Related terms
More in How the web works
Requests and responses