Skip to content

HTTPC

A secure HTTP client library that is secure by default, with built-in smart retries, a middleware chain, and object-pool reuse.

Features

  • TLS 1.2+ - Enforces a minimum TLS version, defaults to TLS 1.2-1.3
  • SSRF Protection - Blocks private IP connections by default, with configurable CIDR exemptions
  • Smart Retries - Exponential backoff with jitter and customizable retry strategies
  • Connection Pool Management - High-performance connection reuse with HTTP/2 support
  • Middleware Chain - Built-in middleware for logging, audit, metrics, recovery, request IDs, and more
  • File Downloads - Resumable downloads, progress callbacks, and checksum verification
  • DNS-over-HTTPS - Built-in DoH resolution to reduce DNS hijacking risk
  • Object Pool Reuse - Internal response objects and string builders are pooled via sync.Pool to reduce GC pressure

Installation

bash
go get github.com/cybergodev/httpc

30-Second Experience

go
package main

import (
    "fmt"
    "github.com/cybergodev/httpc"
)

func main() {
    result, err := httpc.Get("https://httpbin.org/get")
    if err != nil {
        panic(err)
    }

    fmt.Println(result.StatusCode()) // 200
}

Where to Start

Choose a reading path based on your goal:

GoalRecommended
Get started in 5 minutesQuick Start
Hands-on tutorial in 30 minutesTutorial
Look up a usage patternCheat Sheet
Understand security featuresSecurity Overview
Look up API signaturesAPI Reference

Core Concepts

HTTPC offers three usage modes, from simple to flexible:

text
Package-level functions    Client instance               Domain client
httpc.Get()  →  client, _ := httpc.NewDefault()  →  dc, _ := httpc.NewDomainDefault(url)
One-off requests       Custom config/middleware       Session management/automatic cookie handling

Configuration Presets

PresetUse Case
DefaultConfig()General scenarios with secure defaults
SecureConfig()Security-sensitive scenarios with strict timeouts
PerformanceConfig()High throughput with a large connection pool
TestingConfig()Test environments with security checks disabled
MinimalConfig()Lightweight scripts with no retries or redirects