How HTTP Works

Glossary Term

URI vs URL (and URN)

A URL is a URI that says where a resource lives; a URI only identifies it. See the parts of a URL, what the server never receives and parser pitfalls.

Reviewed 2 min readbeginner3 sourcesMarkdown
On this page

TL;DR: URI is the umbrella term for any identifier. A URL is a URI that also locates the resource. In practice, web specs and developers say “URL” for everything you type into an address bar.

A URI (Uniform Resource Identifier) is a string that identifies a resource according to RFC 3986. A URL (Uniform Resource Locator) is a URI that gives the means to reach it, such as a scheme plus network location. A URN names a resource without locating it. All URLs are URIs; the reverse is not true.

Examples

StringURI?URL?
https://example.com/docs?id=7#introYesYes
mailto:dev@example.comYesYes (names a scheme and an address)
urn:isbn:0451450523YesNo (a name, not a location)
/docs?id=7Yes (relative reference)Not by itself

Parts, and what the server sees

https://user@example.com:8443/docs/page?id=7&sort=asc#intro
\___/   \__/ \_________/ \__/ \________/ \__________/ \___/
scheme userinfo host    port  path       query         fragment

A browser sends this on the wire:

GET /docs/page?id=7&sort=asc HTTP/1.1
Host: example.com:8443

The scheme becomes the connection type, the host and port become Host and the TCP target, and the path and query form the request target. The #intro fragment is never sent.

Non-obvious facts

  • The request target is not the URL. In HTTP/1.1 the request line holds only the path and query (origin-form); the host travels in Host. A proxy request uses the full URL (absolute-form).
  • Userinfo in http(s) URLs is deprecated. RFC 9110 tells senders not to generate user:pass@ in http URIs, and browsers strip or warn on it.
  • Parsers disagree. RFC 3986 and the WHATWG URL Standard parse some malformed inputs differently (backslashes, extra slashes, odd hosts), which has caused real SSRF and allowlist bypasses when one component validates and another fetches. Parse once, with one library, and reuse the result.
  • Percent-encoding rules are context-specific. A + means space only in application/x-www-form-urlencoded query data, not in paths.
  • A URI identifies; HTTP dereferences. http://example.com/ can be fetched; a namespace URI like http://www.w3.org/1999/xhtml is just an identifier.

Go deeper

Frequently asked questions

What is the difference between a URI and a URL?

A URI identifies a resource. A URL is a URI that also tells you how to reach it, such as through https:// plus a host and path. Every URL is a URI; not every URI is a URL.

Is a URN a URL?

No. A URN such as urn:isbn:0451450523 names a resource without saying where to get it, so it is a URI but not a URL.

Is the fragment sent to the server?

No. The part after # is handled by the browser, so it never appears in the request line or in server logs.

Why do web specs say URL and not URI?

The WHATWG URL Standard defines the parsing browsers actually implement and uses URL as the one term. RFC 3986 still defines the syntax many servers and libraries use, and the two differ in edge cases.

Sources

  1. RFC 3986: Uniform Resource Identifier (URI) Generic Syntaxrfc-editor.org
  2. WHATWG URL Standardurl.spec.whatwg.org
  3. MDN Web Docs: What is a URL?developer.mozilla.org

Keep going

Browse /search