<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/mWDApVZ8T" -->

---
title: HTTP QUERY: the method that was missing between GET and POST
description: RFC 10008, published by the IETF in June 2026, introduces the HTTP QUERY method — a new verb that combines GET&#x27;s safety and idempotency semantics with POST&#x27;s...
canonical: https://daily.dev/posts/http-query-the-method-that-was-missing-between-get-and-post-mwdapvz8t
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: HTTP QUERY: the method that was missing between GET and POST | daily.dev
og:description: RFC 10008, published by the IETF in June 2026, introduces the HTTP QUERY method — a new verb that combines GET&#x27;s safety and idempotency semantics with POST&#x27;s...
og:url: https://daily.dev/posts/http-query-the-method-that-was-missing-between-get-and-post-mwdapvz8t
og:image: https://api.daily.dev/og/posts/mWDApVZ8T.png
og:image:alt: HTTP QUERY: the method that was missing between GET and POST
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# HTTP QUERY: the method that was missing between GET and POST

**[Codemotion](https://daily.dev/sources/codemotion)** · 12 min read · 11 upvotes · 2 comments

## Summary

RFC 10008, published by the IETF in June 2026, introduces the HTTP QUERY method — a new verb that combines GET's safety and idempotency semantics with POST's ability to carry a request body. This resolves a long-standing dilemma where developers had to choose between GET (limited URI length, sensitive data in logs) and POST (no caching, broken semantics) for complex search queries. QUERY supports content negotiation via the Accept-Query header, body-based caching with normalization caveats, proper redirect handling, and conditional requests. It has significant implications for GraphQL (enabling edge caching without persisted queries), WAF configuration, CORS preflight handling, and GDPR compliance. Backend support already exists in Node.js 21+/22+, Go 1.22+, and OpenAPI 3.2+, though broad ecosystem adoption across proxies, CDNs, and browsers will take years.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.codemotion.com/magazine/backend/http-query-the-method-that-was-missing-between-get-and-post>

## Questions this post answers

### What is the HTTP QUERY method and how is it different from GET and POST?

QUERY is a new HTTP method defined in RFC 10008, published by the IETF in June 2026 as a Proposed Standard. It combines GET's safe and idempotent semantics with POST's ability to carry a request body, letting clients send large or sensitive queries (SQL, JSONPath, GraphQL) without cramming them into a URI or losing caching and idempotency guarantees.

_daily.dev surfaces protocol changes like the QUERY method for engineers deciding how to design their next API._

### Which programming languages and frameworks currently support the HTTP QUERY method?

Node.js's built-in C++ parser supports QUERY natively starting in the 21.x and 22+ branches, with Fastify allowing explicit routing via a hasBody: true flag. Go's net/http package handles it since methods are just strings, and the router introduced in Go 1.22 supports QUERY routing out of the box. OpenAPI 3.2+ also officially documents the method.

_Track emerging runtime and framework support on daily.dev before adopting a new HTTP method in production._

### Why do many WAFs and anti-CSRF middlewares fail to protect HTTP QUERY requests?

Many Web Application Firewalls only deeply inspect request bodies for methods considered unsafe, like POST, PUT, and PATCH, so they may skip inspecting a QUERY request body and let SQL injection or XSS payloads through. Similarly, anti-CSRF middleware may assume QUERY is safe and skip checks, creating a vulnerability if an endpoint is poorly implemented and has side effects.

_Developers hardening APIs against new methods can follow security implications like this on daily.dev._

## Community discussion

Top comments from developers on daily.dev.

**@rizzdev** · 2 upvotes

> POST has carried query bodies for twenty years

## Similar posts on daily.dev

- [Why HTTP needed a new method after 30 years - meet QUERY](https://daily.dev/posts/why-http-needed-a-new-method-after-30-years---meet-query-a5uhffgpn) · Medium · 12 upvotes · 1 comments
- [HTTP gets a QUERY method so complex searches can stop pretending to be POST](https://daily.dev/posts/http-gets-a-query-method-so-complex-searches-can-stop-pretending-to-be-post-mk7367aia) · DEVCLASS · 294 upvotes · 16 comments
- [RFC 10008: The HTTP QUERY Method](https://daily.dev/posts/rfc-10008-the-http-query-method-4azpxbmjt) · Blain Smith · 18 upvotes · 0 comments

---

Tags: [#architecture](https://daily.dev/tags/architecture), [#graphql](https://daily.dev/tags/graphql), [#web-security](https://daily.dev/tags/web-security)

[View this post on daily.dev](https://daily.dev/posts/http-query-the-method-that-was-missing-between-get-and-post-mwdapvz8t)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"HTTP QUERY: the method that was missing between GET and POST","url":"https://daily.dev/posts/http-query-the-method-that-was-missing-between-get-and-post-mwdapvz8t","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/http-query-the-method-that-was-missing-between-get-and-post-mwdapvz8t"},"datePublished":"2026-07-29T12:30:45.313Z","dateModified":"2026-09-13T21:07:12.862Z","description":"RFC 10008, published by the IETF in June 2026, introduces the HTTP QUERY method — a new verb that combines GET's safety and idempotency semantics with POST's...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6dd47825d5214b3d17b81ba506cb1d5d?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6dd47825d5214b3d17b81ba506cb1d5d?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Codemotion","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Codemotion","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/008c4c0fe1ba4cd3b6a6740d442d242b","url":"https://daily.dev/sources/codemotion"},"commentCount":2,"discussionUrl":"https://daily.dev/posts/http-query-the-method-that-was-missing-between-get-and-post-mwdapvz8t","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":11},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":2}],"keywords":"architecture,graphql,web-security","timeRequired":"PT12M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Codemotion","item":"https://daily.dev/sources/codemotion"},{"@type":"ListItem","position":3,"name":"HTTP QUERY: the method that was missing between GET and POST"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/http-query-the-method-that-was-missing-between-get-and-post-mwdapvz8t","comment":[{"@type":"Comment","text":"POST has carried query bodies for twenty years","datePublished":"2026-07-31T04:03:51.027Z","url":"https://daily.dev/posts/mWDApVZ8T#c-B8ndqp6IK","author":{"@type":"Person","name":"Andrew","url":"https://daily.dev/rizzdev","image":"https://media.daily.dev/image/upload/s--35vRfXAA--/f_auto/v1785413727/avatars/avatar_fQ7ttCKtPuu6tDvcgQXv5?_a=BAMAMicg0"},"interactionStatistic":{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2}}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/http-query-the-method-that-was-missing-between-get-and-post-mwdapvz8t#faq","mainEntity":[{"@type":"Question","name":"What is the HTTP QUERY method and how is it different from GET and POST?","acceptedAnswer":{"@type":"Answer","text":"QUERY is a new HTTP method defined in RFC 10008, published by the IETF in June 2026 as a Proposed Standard. It combines GET's safe and idempotent semantics with POST's ability to carry a request body, letting clients send large or sensitive queries (SQL, JSONPath, GraphQL) without cramming them into a URI or losing caching and idempotency guarantees. daily.dev surfaces protocol changes like the QUERY method for engineers deciding how to design their next API."}},{"@type":"Question","name":"Which programming languages and frameworks currently support the HTTP QUERY method?","acceptedAnswer":{"@type":"Answer","text":"Node.js's built-in C++ parser supports QUERY natively starting in the 21.x and 22+ branches, with Fastify allowing explicit routing via a hasBody: true flag. Go's net/http package handles it since methods are just strings, and the router introduced in Go 1.22 supports QUERY routing out of the box. OpenAPI 3.2+ also officially documents the method. Track emerging runtime and framework support on daily.dev before adopting a new HTTP method in production."}},{"@type":"Question","name":"Why do many WAFs and anti-CSRF middlewares fail to protect HTTP QUERY requests?","acceptedAnswer":{"@type":"Answer","text":"Many Web Application Firewalls only deeply inspect request bodies for methods considered unsafe, like POST, PUT, and PATCH, so they may skip inspecting a QUERY request body and let SQL injection or XSS payloads through. Similarly, anti-CSRF middleware may assume QUERY is safe and skip checks, creating a vulnerability if an endpoint is poorly implemented and has side effects. Developers hardening APIs against new methods can follow security implications like this on daily.dev."}}]}
```

