How it works
GET fetches data and should never change anything, which is why browsers, caches and search crawlers feel free to repeat it. POST sends data to create something or trigger an action, such as placing an order. PUT replaces a resource, PATCH updates part of it and DELETE removes it. HEAD asks for the headers only, and OPTIONS asks what is allowed, which browsers use for CORS preflight checks.
Some methods are idempotent, meaning that sending them twice has the same effect as sending them once: GET, PUT and DELETE are, POST is not. That matters when a network hiccup makes a client retry, and it is why payment APIs ask for an idempotency key on POST requests, so a retried payment is not charged twice. REST APIs map these verbs onto create, read, update and delete.
Related terms
More in How the web works
Requests and responses