NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #4146 most downloaded on crates.io
Simple, minimal-dependency HTTP client
Last release 3 months ago
15 Jun 2026
Release timing varies
gaps range from 9 days to 7 months
Most releases are documented
notes for 41 of 46 stable releases
2 versions withdrawn
withdrawn after publishing
9 years old
52 releases · first in 2018
This release includes many breaking changes as implied by the major version bump. See especially the Changed and Deleted sections below.
This changelog is identical to 3.0.0-rc.0, pasted here for convenience.
This release includes many breaking changes as implied by the major version bump. See especially the Changed and Deleted sections below.
This release includes all the planned changes that have been accumulating over the years for 3.0, renames some features, but otherwise tries to keep everything the same as 2.0.
minreq::Error type to be non-exhaustive, to make adding new errors later possible, and added new variants: NativeTlsCreateConnection, OpenSslCreateConnection, InvalidProtocol, and InvalidProtocolInRedirect.Response::headers and ResponseLazy::headers from HashMap<String, String> to Vec<(String, String)>, and removed lowercase normalization of the field names.
Response::header and Response::headers, to get the header value (or all values, if there are multiple of the same header) by field name. In other cases, iterate through and use str::eq_ignore_ascii_case to find your header(s).AsRef<str> instead of Into<String> to avoid unnecessary allocations. Thanks for the PR, @alpha-tango-kilo! (#69)Response::status_code and ResponseLazy::status_code type from i32 to u16. Thanks for the suggestion, @ModProg!https-bundled to https-openssl, https-bundled-probe to https-openssl-probe, and https-native to https-native-tls to make them a little more obvious in what they bring in.Iterator impl for ResponseLazy, see the addition section for more on the new Read impl. Thanks for the PR, @mrkline! (#104)Response::header and Response::headers for ergonomically sorting through the headers of a response, now that they aren't in a convenient HashMap anymore.Read impl for ResponseLazy. This improves performance, and the Read trait generally matches the functionality better than Iterator. Thanks for the PR, @mrkline! (#104)One column per quarter.
Nothing to see here, added some excludes in the Cargo.toml and cleaned up the rustls cert provider dependency feature gates. Just releasing these chan
Nothing to see here, added some excludes in the Cargo.toml and cleaned up the rustls cert provider dependency feature gates. Just releasing these changes as an RC so that the final RC would be identical to the actual 3.0.0 release.
Note that everything under Changed and Removed here is a breaking change .
This is the first release candidate for 3.0. If no issues are found, I'll release 3.0 in a few weeks.
Includes all the planned changes that have been accumulating over the years for 3.0, renames some features, but otherwise tries to keep everything the same as 2.0. Note that everything under Changed and Removed here is a breaking change.
minreq::Error type to be non-exhaustive, to make adding new errors later possible, and added new variants: NativeTlsCreateConnection, OpenSslCreateConnection, InvalidProtocol, and InvalidProtocolInRedirect.Response::headers and ResponseLazy::headers from HashMap<String, String> to Vec<(String, String)>, and removed lowercase normalization of the field names.
Response::header and Response::headers, to get the header value (or all values, if there are multiple of the same header) by field name. In other cases, iterate through and use str::eq_ignore_ascii_case to find your header(s).AsRef<str> instead of Into<String> to avoid unnecessary allocations. Thanks for the PR, @alpha-tango-kilo! (#69)Response::status_code and ResponseLazy::status_code type from i32 to u16. Thanks for the suggestion, @ModProg!https-bundled to https-openssl, https-bundled-probe to https-openssl-probe, and https-native to https-native-tls to make them a little more obvious in what they bring in.Iterator impl for ResponseLazy, see the addition section for more on the new Read impl. Thanks for the PR, @mrkline! (#104)Response::header and Response::headers for ergonomically sorting through the headers of a response, now that they aren't in a convenient HashMap anymore.Read impl for ResponseLazy. This improves performance, and the Read trait generally matches the functionality better than Iterator. Thanks for the PR, @mrkline! (#104)Should be a pretty transparent update, pruning the log dependency for dependents which do not use it, and keeping everything the same for the ones tha
Should be a pretty transparent update, pruning the log dependency for dependents which do not use it, and keeping everything the same for the ones that do.
log crate optional. Thanks for the contribution, @Zodey-hub! (#122)Cleaned up the https-bundled and https-bundled-probe code quite a bit. Now it's more "openssl backend" rather than "native-tls backend but vendored",
Cleaned up the https-bundled and https-bundled-probe code quite a bit. Now it's more "openssl backend" rather than "native-tls backend but vendored", so the features might change their names to https-openssl in the next major version, whenever that ends up happening.
Also, added a new option for requests, Request::with_follow_redirects, which can be used to disable redirection, for cases where you want to read the redirection HTTP responses themselves.
https-bundled, https-bundled-probe: Removed almost all of the bundled native-tls code (~1k LoC), only keeping the relevant part (~30 LoC). There should be no change to the actual code that ends up being ran, but if you're using these features, make sure to test that everything works as you expect, something might have slipped.https-*: Refactored the TLS handling code a bit. This should have no visible effect downstream, src/connection.rs is just a little bit more readable now.build.rs, which turned out to be dead code. This should have no effect, but if it does, it should also only affect the https-bundled and https-bundled-probe features.Request::with_follow_redirects for disabling redirection handling. Thanks for the suggestion, @tachibanayui! (#120)Updated the base64 dependency, only used by the proxy feature, to its newest minor version. Thanks for the report, @Jackhr-arch !
proxy feature, to its newest minor version. Thanks for the report, @Jackhr-arch! (#119)A bit of dependency cleanup, and updated the list of crates that need to be pinned to build with MSRV.
A bit of dependency cleanup, and updated the list of crates that need to be pinned to build with MSRV.
once_cell dependency by making use of the new std::sync::OnceLock type. This change only affects the rustls-based https features. Thanks for the PR, @LyonSyonII! (#115)rustix update. Now tempfile is pinned as well."Cleaned up" some code in 2.13.1, thinking that minreq doesn't have a build.rs, but it does, and the code could actually be enabled via an environment
"Cleaned up" some code in 2.13.1, thinking that minreq doesn't have a build.rs, but it does, and the code could actually be enabled via an environment variable. Reverted that bit here.
Usage of an openssl-probe function that's deprecated due to safety issues. See rustsec/advisory-db#2209 for further info.
Only affects builds using the https-bundled-probe feature.
This is a tiny update to the copied-over native-tls cert loading code when using openssl-probe without native-tls, to avoid an apparently unsafe function in openssl-probe.
Small fixups all around, mostly code size improvements. In case your application depends specifically on webpki-roots certs being used, but still uses
Small fixups all around, mostly code size improvements. In case your application depends specifically on webpki-roots certs being used, but still uses the https-rustls-probe feature, I'm afraid you'll have to stay on 2.12. I hope this isn't the case for anyone.
Also: periodic MSRV CI did its job! It took me 5 days to notice the notification, but still a big improvement in issue-appearance-to-fix-latency.
https-rustls-probe feature no longer brings in the webpki-roots and rustls-webpki crates. Thanks for the report, @polarathene! (#111)Request::with_headers, to allow passing in many headers at a time. Thanks for the idea and PR, @rawhuul!
The dev dependency tiny_http's version up to 0.12. Thanks for the PR, @davide125!
Unnecessary buffering causing performance problems. Thanks for the PRs, @mrkline! (#102, #103)
Removed upper bounds on the serde_json, log and chrono dependencies (dev-dependency in the case of chrono). If you were depending on minreq compiling
serde_json, log and chrono
dependencies (dev-dependency in the case of chrono). If you were
depending on minreq compiling with the MSRV compiler without any
issues, check out the MSRV section in the readme, it's been updated
with additional instructions. Thanks for the report, @RCasatta!
(#99)Fragment handling, once again. Turns out you're not supposed to include fragments in the request. This may break usage with servers that are written w
Response::url and ResponseLazy::url fields, to contain the final URL after
redirects and fragment replacement semantics.Loosened the rustls version requirement from 0.21.6 to 0.21.1.
From webpki to rustls-webpki. Thanks for the heads-up about webpki not being maintained, @RCasatta!
>=1.0.0, <1.0.101)>=0.4.0, <0.4.19)>=0.4.0, <0.4.24)Proxy strings with the protocol included not working. Thanks for the report, @tkkcc!
Default proxy from environment variables when the proxy feature is enabled, based on what curl does. Thanks for the PR, @krypt0nn!
proxy feature is
enabled, based on what curl does. Thanks for the PR, @krypt0nn!
(#94)From lazy_static to once_cell for library internals. Thanks for the PR, @alpha-tango-kilo!
--all-features, with the send_https function defaulting to
the rustls-based implementation. Thanks for the PR, @tcharding!
(#89)The error returned when the request url does not start with https:// or http:// now is now a slightly different IoError, with a clearer message. This
https:// or http:// now is now a slightly different IoError,
with a clearer message. This will be changed to a proper
minreq-specific error in 3.0, but for now it's an IoError to avoid
breaking the Error type.GitHub API requests without User-Agent returning an IoError. Thanks for the report, @tech-ticks!
Returning the wrong status code when the response was missing a status phrase. Thanks for the PR, @richarddd!
A regression in 2.4.1 where the port is no longer included in the Host, even if it's a non-standard port. Now the port is always included if it's in t
Host, even if it's a non-standard port. Now the port is always
included if it's in the request URL, and omitted if the port is
implied. Thanks for the report, @ollpu!
(#61)The port is no longer included in the Host header when sending requests, and port handling was cleaned up overall. This fixes issues with infinite red
Host header when sending
requests, and port handling was cleaned up overall. This fixes
issues with infinite redirections and https handshakes for some
websites. Thanks to @Shnatsel for reporting the issues, and @joeried
for debugging and figuring out the root cause of these problems!
(#48,
#49)Request::with_param for more ergonomic query parameter usage. Thanks for the PR, @sjvignesh!
Request::with_param for more ergonomic query parameter
usage. Thanks for the PR, @sjvignesh!
(#54)Request::with_max_headers_size and
Request::with_max_status_line_length for avoiding DoS when the
server sends large headers or status lines. Thanks for the report,
@Shnatsel! (#55)rustls-native-certs crate via a new
https-rustls-probe feature. Thanks for the PR, @joeried!
(#59)Removed some leftover printlns from the redirection update in 2.3.0 and ensured there's no printlns in the library anymore. Thanks for reporting the i
Breaking (sort of): the redirection code was improved to match RFC 7231 section 7.1.2, which could subtly break some programs relying on very specific
Location does
not, the original fragment should be included in the new url. If
Location does have a fragment, it should override the one in the
redirecting url.Location is
relative, e.g. /Foo.html instead of
https://example.com/Foo.html. Thanks, @fjt523!Content-Length: 0 header is now inserted into requests that
should have it. Thanks, @KarthikNedunchezhiyan!Some documentation which has been long due for an update. I just always forget when writing an actual update. No code changes!
Support for native-tls and openssl-sys via new features, in addition to rustls. Thanks to @dubiousjim!
native-tls and openssl-sys via new features, in
addition to rustls. Thanks to @dubiousjim!Handling of status codes 204 and 304. Thanks to @Mubelotix!
Proxy support via the proxy feature. Thanks to @rustysec!
proxy feature. Thanks to @rustysec!Fixed regression in header parsing caused by 2.0.2, which was yanked.
Fixed a panic when sending a request to an invalid domain via https.
Made timeouts work as described in the documentation. Fixed issue #22.
API for loading the HTTP response body through an iterator, allowing for processing of the data during the download.
ResponseLazy documentation for more information.? usage and better debuggability.punycode feature.hello,
iterator, and json.response.headers.get("Content-Type"), you have to change it to
response.headers.get("content-type"), or it will not return what
you want.Response struct:
bytes and body_bytes.as_bytes(), into_bytes(), and as_str() in their place.with_body parameter type to
Into<Vec<u8>> from Into<String>.
Strings implement Into<Vec<u8>>, so this shouldn't cause any
problems, unless you're using some interesting types that
implement Into<String> but not Into<Vec<u8>>.panic! when trying to make an https:// request without
the https feature. The request will now return an error
instead. The library should not panic anymore.unwrap()s from library code, none of them
should actually ever cause a panic now.create_request in favor of just using Response::new.Nothing published for this version
Nothing published for this version
Tests on Windows by changing the ip in tests from 0.0.0.0 to localhost.
0.0.0.0 to
localhost.rustls::ClientConfig between requests.Content-Length and Transfer-Encoding detection failing because
of case-sensitiveness.### Added - json-using-serde feature.
json-using-serde feature.The body_bytes field to Response, containing the body in raw bytes.
body_bytes field to Response, containing the body in raw
bytes.body
string to an empty string, for now.### Fixed - HTTP response body handling.
Support for the HTTP status codes 301, 302, 303, and 307.
Fix response handling when Transfer-Encoding is chunked.
Transfer-Encoding is chunked.HEAD requests and ones that receive a 1xx, 204, or 304 status code as a response.
Improved performance for HTTP (not HTTPS) requests.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →