http.placeholder.com

HTTP test endpoints

An endpoint for every HTTP behaviour your client has to handle: echo the request, return any status code, redirect, ask for credentials, set cookies, answer conditional requests, stall, trickle, stream and serve byte ranges. httpbin-compatible where it makes sense, and safe to point at from anywhere.

curl 'https://http.placeholder.com/get?foo=bar'
curl -X POST -H 'Content-Type: application/json' -d '{"a":1}' https://http.placeholder.com/post
curl -i https://http.placeholder.com/status/503
curl -L https://http.placeholder.com/redirect/3

The index at https://http.placeholder.com/ lists every endpoint, with an example and the limits, as JSON.

Inspect the request

EndpointMethodsReturns
/getGETQuery args, headers, origin IP and url
/post, /put, /patch, /deletethat methodThe same plus the body: data, form, files, json
/anything[/any/path]anyEcho of any method and path, always JSON
/headers, /ip, /user-agentGETJust that part
/uuidGETA random UUID4

Status codes

Accepts GET, POST, PUT, PATCH and DELETE. Redirect codes come with Location, 401 and 407 with an auth challenge, 429 and 503 with Retry-After: 1; 204, 205 and 304 have no body. Up to 20 codes per list.

Redirects

/redirect-to only goes to relative paths or http.placeholder.com itself. It is not an open redirect: other hosts are a 400.

Auth and cookies

curl -u user:passwd https://http.placeholder.com/basic-auth/user/passwd
curl -H 'Authorization: Bearer test-token' https://http.placeholder.com/bearer

Cookies are host-only, at most 5 per request, values up to 128 characters; names starting with __Host-, __Secure- or cf are refused.

Caching

Slow, streamed and partial responses

curl -H 'Range: bytes=0-99' -i https://http.placeholder.com/range/1024
curl -N 'https://http.placeholder.com/sse?count=5&interval=1'

Formats and encodings

/response-headers adds up to 10 headers: X- headers and a few harmless standard ones (ETag, Last-Modified, Retry-After, Server-Timing, Content-Language, Warning, Allow, Accept-Ranges). Never Content-Type, Location, Set-Cookie or security headers.

Limits

WhatLimit
Request body echoed1 MB, 100 fields, JSON nesting 64
/delay10 s
Redirect hops20
/bytes, /stream-bytes10 MB
/stream100 lines
/range100 KB
/drip10 KB over at most 10 s
/sse100 events, interval up to 5 s, 60 s in total

Out-of-range values are a 400 with a JSON error, never silently clamped. Errors look like {"error": "…", "status": 400}. When the server is saturated with slow requests it answers 503 with Retry-After: 5.

Safe by design