Glossary Term
URI vs URL (and URN)
A URL is a URI that says where a resource lives; a URI only identifies it. See the parts of a URL, what the server never receives and parser pitfalls.
TL;DR: URI is the umbrella term for any identifier. A URL is a URI that also locates the resource. In practice, web specs and developers say “URL” for everything you type into an address bar.
A URI (Uniform Resource Identifier) is a string that identifies a resource according to RFC 3986. A URL (Uniform Resource Locator) is a URI that gives the means to reach it, such as a scheme plus network location. A URN names a resource without locating it. All URLs are URIs; the reverse is not true.
Examples
| String | URI? | URL? |
|---|---|---|
https://example.com/docs?id=7#intro | Yes | Yes |
mailto:dev@example.com | Yes | Yes (names a scheme and an address) |
urn:isbn:0451450523 | Yes | No (a name, not a location) |
/docs?id=7 | Yes (relative reference) | Not by itself |
Parts, and what the server sees
https://user@example.com:8443/docs/page?id=7&sort=asc#intro
\___/ \__/ \_________/ \__/ \________/ \__________/ \___/
scheme userinfo host port path query fragment
A browser sends this on the wire:
GET /docs/page?id=7&sort=asc HTTP/1.1
Host: example.com:8443
The scheme becomes the connection type, the host and port become Host and the TCP target, and the path and query form the request target. The #intro fragment is never sent.
Non-obvious facts
- The request target is not the URL. In HTTP/1.1 the request line holds only the path and query (origin-form); the host travels in
Host. A proxy request uses the full URL (absolute-form). - Userinfo in
http(s)URLs is deprecated. RFC 9110 tells senders not to generateuser:pass@in http URIs, and browsers strip or warn on it. - Parsers disagree. RFC 3986 and the WHATWG URL Standard parse some malformed inputs differently (backslashes, extra slashes, odd hosts), which has caused real SSRF and allowlist bypasses when one component validates and another fetches. Parse once, with one library, and reuse the result.
- Percent-encoding rules are context-specific. A
+means space only inapplication/x-www-form-urlencodedquery data, not in paths. - A URI identifies; HTTP dereferences.
http://example.com/can be fetched; a namespace URI likehttp://www.w3.org/1999/xhtmlis just an identifier.
Go deeper
Frequently asked questions
What is the difference between a URI and a URL?
A URI identifies a resource. A URL is a URI that also tells you how to reach it, such as through https:// plus a host and path. Every URL is a URI; not every URI is a URL.
Is a URN a URL?
No. A URN such as urn:isbn:0451450523 names a resource without saying where to get it, so it is a URI but not a URL.
Is the fragment sent to the server?
No. The part after # is handled by the browser, so it never appears in the request line or in server logs.
Why do web specs say URL and not URI?
The WHATWG URL Standard defines the parsing browsers actually implement and uses URL as the one term. RFC 3986 still defines the syntax many servers and libraries use, and the two differ in edge cases.
Sources
Related
Host Header
Learn how the Host header specifies the target server domain name and port for HTTP requests. Essential for virtual hosting and routing on shared servers.
Location
Learn how the Location header specifies redirect URLs or the location of newly created resources. Essential for 201, 301, 302, and other redirect responses.
Referer Header: What It Sends and How to Control It
Referer tells a server which page a request came from. What browsers send under the default strict-origin-when-cross-origin policy, and how to trim it.
What Is HTTP? How the HTTP Protocol Works
HTTP is the request-response protocol behind every web page and API. See a real request and response, then methods, headers, status codes and what HTTPS adds.