Skip to content

httpx

Multipurpose HTTP toolkit for fast probing and scanning of HTTP services to reveal status codes, technologies and endpoints.

Self-hostedNot yet verified
Report issue
MIT★ 12000Source project only — not browser-runnable

External Tool

This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.

Browse security tools →

What's next with httpx?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is httpx?

httpx is an open-source HTTP toolkit designed for efficient and reliable probing of web assets. It leverages the retryablehttp library to handle complex scenarios like Web Application Firewalls (WAFs) and network instability, ensuring consistent results even under challenging conditions. The tool is widely used by cybersecurity professionals, penetration testers, and developers who need to validate HTTP endpoints, assess server configurations, or automate tasks requiring HTTP interactions. Its primary purpose is to streamline the process of checking multiple URLs, hosts, or CIDR ranges while maintaining reliability through advanced retry mechanisms and thread management. By abstracting low-level HTTP operations, httpx reduces the complexity of building custom HTTP clients, making it a versatile tool for both routine and specialized workflows.

How it works

httpx is a fast, multi-purpose HTTP toolkit that simplifies the process of probing web assets by handling multiple HTTP requests simultaneously. It is built with a modular architecture, allowing users to extend its functionality while maintaining performance. The tool's core purpose is to provide reliable HTTP checks by incorporating retry logic, backoff strategies, and intelligent fallback mechanisms. This makes it particularly effective for tasks requiring resilience against network issues or WAF interference. httpx supports probing URLs, hosts, and CIDR ranges, with features like automatic HTTPS-to-HTTP fallback and configurable concurrency levels. It integrates with the retryablehttp library to handle retries and backoffs, ensuring in unstable environments. The tool also includes built-in probes for checking server headers, title tags, and other metadata, which are critical for reconnaissance and vulnerability assessment.

How to use it

  1. 1Install httpx via Go: `go get -u github.com/projectdiscovery/httpx`.
  2. 2Run the tool with input files: `httpx -u urls.txt` to probe URLs.
  3. 3Use flags like `-t` for thread count and `-r` for retries to customize behavior.
  4. 4Analyze output, which includes status codes, headers, and response times for each target. Practical tips: Use `-k` to skip SSL verification for testing, and `-c` to enable certificate checks for secure connections. Always validate input files for malformed URLs before execution.

What it can do

  • HTTP probing tool

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/projectdiscovery/httpx
  • license: MIT — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Relies on network connectivity and may fail in restricted environments
  • Lacks built-in support for advanced TLS protocols beyond basic validation
  • Does not include GUI tools, requiring command-line proficiency
  • Limited to HTTP/1.1; does not natively support HTTP/2 or QUIC
  • Requires manual configuration for custom probe logic

Understanding the result

Multipurpose HTTP toolkit for fast probing and scanning of HTTP services to reveal status codes, technologies and endpoints.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(projectdiscovery/httpx)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with projectdiscovery/httpx. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

How does httpx handle Web Application Firewalls (WAFs)?

httpx incorporates retry logic and backoff strategies to mitigate WAF interference. It automatically retries failed requests with adjusted headers and timing, reducing the likelihood of triggering rate limits or blocking mechanisms. The tool's modular design also allows users to customize request headers to bypass specific WAF rules.

What protocols does httpx support?

httpx primarily supports HTTP/1.1 out of the box. While it can handle HTTPS via standard TLS libraries, advanced protocols like HTTP/2 or QUIC require additional configuration or integration with other tools. The retryablehttp library ensures compatibility with most common server implementations.

How can I check if a server responds with a specific header?

Use the `-H` flag to specify custom headers, such as `httpx -u example.com -H 'User-Agent: custom-agent'`. To filter results based on headers, combine it with tools like `grep` or `jq` for parsing. For example: `httpx -u targets.txt | grep 'Server: Apache'`.

How does httpx compare to curl or wfuzz?

httpx is optimized for bulk HTTP probing with built-in retry logic and concurrency, making it faster than manual curl commands for large workloads. Unlike wfuzz, which focuses on fuzzing URLs, httpx excels at validating existing endpoints. It also offers better reliability for WAF bypass testing compared to basic tools.

What should I do if httpx reports a 'connection refused' error?

A 'connection refused' error typically indicates the target is unreachable. Verify the target's IP and port, check for firewall rules blocking traffic, and ensure the server is online. Use the `-k` flag to skip SSL verification if the issue is related to certificate validation. If the problem persists, the target may be offline or misconfigured.

Spotted something wrong with httpx, or want to maintain it? See how to help.