minreq
Simple, minimal-dependency HTTP client
3.0.0
6.2M downloads/mo
#4043 most downloaded on crates.io
neonmoe/minreq
What this package is like to depend on
Last release 2 months ago
15 Jun 2026
Release timing varies
gaps range from 9 days to 7 months
Most releases are documented
notes for 41 of 46 stable releases
2 versions withdrawn
withdrawn after publishing
8 years old
52 releases · first in 2018
4 releases in the last 12 months
see the full history below
Release timeline
52 releases · Mar 2018 to Jun 2026Releases
latest 52-
3.0.015 Jun 2026Release notes
Open source →This changelog is identical to 3.0.0-rc.0, pasted here for convenience.
This release includes many breaking changes as implied by the major version bump. See especially the Changed and Deleted sections below.
This release includes all the planned changes that have been accumulating over the years for 3.0, renames some features, but otherwise tries to keep everything the same as 2.0.
Changed
- MSRV from 1.48 to 1.63, and updated the policy to be looser (now tracking Debian oldstable's Rust version instead of settling on a specific version until eternity, and the MSRV no longer applies to any optional features).
- The
minreq::Errortype to be non-exhaustive, to make adding new errors later possible, and added new variants:NativeTlsCreateConnection,OpenSslCreateConnection,InvalidProtocol, andInvalidProtocolInRedirect. - The default proxy port to 1080, to match curl.
- The default maximum sizes for the response status line and headers, both 8KiB.
- The type of
Response::headersandResponseLazy::headersfromHashMap<String, String>toVec<(String, String)>, and removed lowercase normalization of the field names.- To help the usual case, there's two new functions,
Response::headerandResponse::headers, to get the header value (or all values, if there are multiple of the same header) by field name. In other cases, iterate through and usestr::eq_ignore_ascii_caseto find your header(s).
- To help the usual case, there's two new functions,
- The query parameter function to take
AsRef<str>instead ofInto<String>to avoid unnecessary allocations. Thanks for the PR, @alpha-tango-kilo! (#69) Response::status_codeandResponseLazy::status_codetype fromi32tou16. Thanks for the suggestion, @ModProg!
(#118)- Renamed features
https-bundledtohttps-openssl,https-bundled-probetohttps-openssl-probe, andhttps-nativetohttps-native-tlsto make them a little more obvious in what they bring in.
Removed
Iteratorimpl forResponseLazy, see the addition section for more on the newReadimpl. Thanks for the PR, @mrkline! (#104)
Added
Response::headerandResponse::headersfor ergonomically sorting through the headers of a response, now that they aren't in a convenientHashMapanymore.Readimpl forResponseLazy. This improves performance, and theReadtrait generally matches the functionality better thanIterator. Thanks for the PR, @mrkline! (#104)
Release notes
Open source →Changed
- MSRV from 1.48 to 1.63, and updated the policy to be looser (now tracking Debian oldstable's Rust version instead of settling on a specific version until eternity, and the MSRV no longer applies to any optional features).
- The
minreq::Errortype to be non-exhaustive, to make adding new errors later possible, and added new variants:NativeTlsCreateConnection,OpenSslCreateConnection,InvalidProtocol, andInvalidProtocolInRedirect. - The default proxy port to 1080, to match curl.
- The default maximum sizes for the response status line and headers, both 8KiB.
- The type of
Response::headersandResponseLazy::headersfromHashMap<String, String>toVec<(String, String)>, and removed lowercase normalization of the field names.- To help the usual case, there's two new functions,
Response::headerandResponse::headers, to get the header value (or all values, if there are multiple of the same header) by field name. In other cases, iterate through and usestr::eq_ignore_ascii_caseto find your header(s).
- To help the usual case, there's two new functions,
- The query parameter function to take
AsRef<str>instead ofInto<String>to avoid unnecessary allocations. Thanks for the PR, @alpha-tango-kilo! (#69) Response::status_codeandResponseLazy::status_codetype fromi32tou16. Thanks for the suggestion, @ModProg! (#118)- Renamed features
https-bundledtohttps-openssl,https-bundled-probetohttps-openssl-probe, andhttps-nativetohttps-native-tlsto make them a little more obvious in what they bring in.
Removed
Iteratorimpl forResponseLazy, see the addition section for more on the newReadimpl. Thanks for the PR, @mrkline! (#104)
Added
Response::headerandResponse::headersfor ergonomically sorting through the headers of a response, now that they aren't in a convenientHashMapanymore.Readimpl forResponseLazy. This improves performance, and theReadtrait generally matches the functionality better thanIterator. Thanks for the PR, @mrkline! (#104)
-
3.0.0-rc.121 Apr 2026 pre-releaseRelease notes
Open source →Nothing to see here, added some excludes in the Cargo.toml and cleaned up the rustls cert provider dependency feature gates. Just releasing these changes as an RC so that the final RC would be identical to the actual 3.0.0 release.
-
3.0.0-rc.012 Apr 2026 pre-releaseRelease notes
Open source →This is the first release candidate for 3.0. If no issues are found, I'll release 3.0 in a few weeks.
Includes all the planned changes that have been accumulating over the years for 3.0, renames some features, but otherwise tries to keep everything the same as 2.0. Note that everything under Changed and Removed here is a breaking change.
Changed
- MSRV from 1.48 to 1.63, and updated the policy to be looser (now tracking Debian oldstable's Rust version instead of settling on a specific version until eternity, and the MSRV no longer applies to any optional features).
- The
minreq::Errortype to be non-exhaustive, to make adding new errors later possible, and added new variants:NativeTlsCreateConnection,OpenSslCreateConnection,InvalidProtocol, andInvalidProtocolInRedirect. - The default proxy port to 1080, to match curl.
- The default maximum sizes for the response status line and headers, both 8KiB.
- The type of
Response::headersandResponseLazy::headersfromHashMap<String, String>toVec<(String, String)>, and removed lowercase normalization of the field names.- To help the usual case, there's two new functions,
Response::headerandResponse::headers, to get the header value (or all values, if there are multiple of the same header) by field name. In other cases, iterate through and usestr::eq_ignore_ascii_caseto find your header(s).
- To help the usual case, there's two new functions,
- The query parameter function to take
AsRef<str>instead ofInto<String>to avoid unnecessary allocations. Thanks for the PR, @alpha-tango-kilo! (#69) Response::status_codeandResponseLazy::status_codetype fromi32tou16. Thanks for the suggestion, @ModProg!
(#118)- Renamed features
https-bundledtohttps-openssl,https-bundled-probetohttps-openssl-probe, andhttps-nativetohttps-native-tlsto make them a little more obvious in what they bring in.
Removed
Iteratorimpl forResponseLazy, see the addition section for more on the newReadimpl. Thanks for the PR, @mrkline! (#104)
Added
Response::headerandResponse::headersfor ergonomically sorting through the headers of a response, now that they aren't in a convenientHashMapanymore.Readimpl forResponseLazy. This improves performance, and theReadtrait generally matches the functionality better thanIterator. Thanks for the PR, @mrkline! (#104)
-
2.14.103 Sep 2025Release notes
Open source →Should be a pretty transparent update, pruning the log dependency for dependents which do not use it, and keeping everything the same for the ones that do.
Fixed
- Made the
logcrate optional. Thanks for the contribution, @Zodey-hub! (#122)
Release notes
Open source →Fixed
- Made the
logcrate optional. Thanks for the contribution, @Zodey-hub! (#122)
- Made the
-
2.14.027 Jun 2025Release notes
Open source →Cleaned up the
https-bundledandhttps-bundled-probecode quite a bit. Now it's more "openssl backend" rather than "native-tls backend but vendored", so the features might change their names tohttps-opensslin the next major version, whenever that ends up happening.Also, added a new option for requests,
Request::with_follow_redirects, which can be used to disable redirection, for cases where you want to read the redirection HTTP responses themselves.Changed
https-bundled,https-bundled-probe: Removed almost all of the bundled native-tls code (~1k LoC), only keeping the relevant part (~30 LoC). There should be no change to the actual code that ends up being ran, but if you're using these features, make sure to test that everything works as you expect, something might have slipped.
Fixed
https-*: Refactored the TLS handling code a bit. This should have no visible effect downstream,src/connection.rsis just a little bit more readable now.- Removed
build.rs, which turned out to be dead code. This should have no effect, but if it does, it should also only affect thehttps-bundledandhttps-bundled-probefeatures.
Added
Request::with_follow_redirectsfor disabling redirection handling. Thanks for the suggestion, @tachibanayui! (#120)
Release notes
Open source →Changed
https-bundled,https-bundled-probe: Removed almost all of the bundled native-tls code (~1k LoC), only keeping the relevant part (~30 LoC). There should be no change to the actual code that ends up being ran, but if you're using these features, make sure to test that everything works as you expect, something might have slipped.
Fixed
https-*: Refactored the TLS handling code a bit. This should have no visible effect downstream,src/connection.rsis just a little bit more readable now.- Removed
build.rs, which turned out to be dead code. This should have no effect, but if it does, it should also only affect thehttps-bundledandhttps-bundled-probefeatures.
Added
Request::with_follow_redirectsfor disabling redirection handling. Thanks for the suggestion, @tachibanayui! (#120)
-
2.13.411 Apr 2025Release notes
Open source →Fixed
- Updated the base64 dependency, only used by the
proxyfeature, to its newest minor version. Thanks for the report, @Jackhr-arch! (#119)
Release notes
Open source →Fixed
- Updated the base64 dependency, only used by the
proxyfeature, to its newest minor version. Thanks for the report, @Jackhr-arch! (#119)
- Updated the base64 dependency, only used by the
-
2.13.311 Mar 2025Release notes
Open source →A bit of dependency cleanup, and updated the list of crates that need to be pinned to build with MSRV.
Fixed
- Removed the
once_celldependency by making use of the newstd::sync::OnceLocktype. This change only affects the rustls-based https features. Thanks for the PR, @LyonSyonII! (#115) - MSRV builds that got broken due to a
rustixupdate. Nowtempfileis pinned as well.
Release notes
Open source →Fixed
- Removed the
once_celldependency by making use of the newstd::sync::OnceLocktype. This change only affects the rustls-based https features. Thanks for the PR, @LyonSyonII! (#115) - MSRV builds that got broken due to a
rustixupdate. Nowtempfileis pinned as well.
- Removed the
-
2.13.229 Jan 2025Release notes
Open source →"Cleaned up" some code in 2.13.1, thinking that minreq doesn't have a build.rs, but it does, and the code could actually be enabled via an environment variable. Reverted that bit here.
Fixed
- Reverted a part of 2.13.1, accidentally removed some code that wasn't actually dead code.
Release notes
Open source →Fixed
- Reverted a part of 2.13.1, accidentally removed some code that wasn't actually dead code.
-
2.13.129 Jan 2025Release notes
Open source →Only affects builds using the
https-bundled-probefeature.This is a tiny update to the copied-over native-tls cert loading code when using
openssl-probewithoutnative-tls, to avoid an apparently unsafe function inopenssl-probe.Fixed
- Usage of an openssl-probe function that's deprecated due to safety issues. See rustsec/advisory-db#2209 for further info.
Release notes
Open source →Fixed
- Usage of an openssl-probe function that's deprecated due to safety issues. See rustsec/advisory-db#2209 for further info.
-
2.13.004 Dec 2024Release notes
Open source →Small fixups all around, mostly code size improvements. In case your application depends specifically on
webpki-rootscerts being used, but still uses thehttps-rustls-probefeature, I'm afraid you'll have to stay on 2.12. I hope this isn't the case for anyone.Also: periodic MSRV CI did its job! It took me 5 days to notice the notification, but still a big improvement in issue-appearance-to-fix-latency.
Changed
- The
https-rustls-probefeature no longer brings in thewebpki-rootsandrustls-webpkicrates. Thanks for the report, @polarathene! (#111)
Fixed
Release notes
Open source →Changed
- The
https-rustls-probefeature no longer brings in thewebpki-rootsandrustls-webpkicrates. Thanks for the report, @polarathene! (#111)
Fixed
- Cleaned up an unnecessary
format!()inConnection::connect. Thanks for the PR, @melotic! (#112) - Fixed some msrv and lint issues introduced by libc and clippy updates respectively.
- The
-
2.12.016 Jul 2024Release notes
Open source →Added
- Request::with_headers, to allow passing in many headers at a time. Thanks for the idea and PR, @rawhuul! (#110)
-
2.11.226 Apr 2024Release notes
Open source →Fixed
- The dev dependency tiny_http's version up to 0.12. Thanks for the PR, @davide125! (#107)
-
2.11.102 Apr 2024 -
2.11.017 Oct 2023Release notes
Open source →Changed
- Removed upper bounds on the
serde_json,logandchronodependencies (dev-dependency in the case ofchrono). If you were depending on minreq compiling with the MSRV compiler without any issues, check out the MSRV section in the readme, it's been updated with additional instructions. Thanks for the report, @RCasatta! (#99)
- Removed upper bounds on the
-
2.10.005 Sep 2023Release notes
Open source →Fixed
- Fragment handling, once again. Turns out you're not supposed to include fragments in the request. This may break usage with servers that are written with the wrong assumptions. Thanks for the report, @rawhuul! (#100)
Added
Response::urlandResponseLazy::urlfields, to contain the final URL after redirects and fragment replacement semantics.
-
2.9.128 Aug 2023 -
2.9.024 Aug 2023Release notes
Open source →Changed
- From webpki to rustls-webpki. Thanks for the heads-up about webpki not being maintained, @RCasatta! (#98)
- Updated rustls and webpki-roots to their most recent versions.
- Maximum versions for the following dependencies to keep minreq compiling on
Rust 1.48:
- serde_json (
>=1.0.0, <1.0.101) - log (
>=0.4.0, <0.4.19) - chrono (dev-dependency,
>=0.4.0, <0.4.24)
- serde_json (
Fixed
- Errors when using an IP address as the host with HTTPS (tested with https://8.8.8.8). (#34)
-
2.8.120 May 2023Release notes
Open source →Fixed
- Proxy strings with the protocol included not working. Thanks for the report, @tkkcc! (#95)
-
2.8.012 May 2023Release notes
Open source →Added
- Default proxy from environment variables when the
proxyfeature is enabled, based on what curl does. Thanks for the PR, @krypt0nn! (#94)
- Default proxy from environment variables when the
-
2.7.019 Mar 2023Release notes
Open source →Changed
- From lazy_static to once_cell for library internals. Thanks for the PR, @alpha-tango-kilo! (#80)
Added
- A Read impl for ResponseLazy. Thanks for the PR, @Luro02! (#81)
- Building with
--all-features, with thesend_httpsfunction defaulting to the rustls-based implementation. Thanks for the PR, @tcharding! (#89) - An explicit minimum supported rust version policy. The MSRV for versions 2.x is 1.48. Thanks for the suggestion and PR, @tcharding! (#90)
- Performance improvements, test fixes, CI updates.
-
2.6.023 Feb 2022Release notes
Open source →Changed
- The error returned when the request url does not start with
https://orhttp://now is now a slightly different IoError, with a clearer message. This will be changed to a proper minreq-specific error in 3.0, but for now it's an IoError to avoid breaking the Error type.
Added
- The error returned when the request url does not start with
-
2.5.106 Jan 2022Release notes
Open source →Fixed
- GitHub API requests without User-Agent returning an IoError. Thanks for the report, @tech-ticks! (#66)
-
2.5.006 Jan 2022 -
2.4.211 Jun 2021Release notes
Open source →Fixed
- A regression in 2.4.1 where the port is no longer included in the
Host, even if it's a non-standard port. Now the port is always included if it's in the request URL, and omitted if the port is implied. Thanks for the report, @ollpu! (#61)
- A regression in 2.4.1 where the port is no longer included in the
-
2.4.105 Jun 2021Release notes
Open source →Fixed
- The port is no longer included in the
Hostheader when sending requests, and port handling was cleaned up overall. This fixes issues with infinite redirections and https handshakes for some websites. Thanks to @Shnatsel for reporting the issues, and @joeried for debugging and figuring out the root cause of these problems! (#48, #49)
- The port is no longer included in the
-
2.4.027 May 2021Release notes
Open source →Added
Request::with_paramfor more ergonomic query parameter usage. Thanks for the PR, @sjvignesh! (#54)Request::with_max_headers_sizeandRequest::with_max_status_line_lengthfor avoiding DoS when the server sends large headers or status lines. Thanks for the report, @Shnatsel! (#55)- Support for the
rustls-native-certscrate via a newhttps-rustls-probefeature. Thanks for the PR, @joeried! (#59)
Fixed
-
2.3.110 Feb 2021Release notes
Open source →Fixed
- Removed some leftover printlns from the redirection update in 2.3.0 and ensured there's no printlns in the library anymore. Thanks for reporting the issue @Shnatsel! #45
- Fixed the timeout not being respected during the initial TCP connect. Thanks for the report and fix @KarthikNedunchezhiyan! #46, #47
-
2.3.004 Jan 2021Release notes
Open source →Changed
- Breaking (sort of): the redirection code was improved to match
RFC 7231 section
7.1.2, which
could subtly break some programs relying on very specific redirects,
which is why this should be investigated if you come across weird
behaviour after updating. No API changes though, so only a minor
version bump. The following two points are now fixed when
redirecting:
- Fragments, the bit after a #-character in the url. If the
redirecting url has a fragment, and the one in
Locationdoes not, the original fragment should be included in the new url. IfLocationdoes have a fragment, it should override the one in the redirecting url. - Relative urls. Minreq now properly redirects when
Locationis relative, e.g./Foo.htmlinstead ofhttps://example.com/Foo.html. Thanks, @fjt523!
- Fragments, the bit after a #-character in the url. If the
redirecting url has a fragment, and the one in
Fixed
- The
Content-Length: 0header is now inserted into requests that should have it. Thanks, @KarthikNedunchezhiyan! - Status line parsing is now fixed, so "400 Bad Request" is not parsed as "400 Bad". Thanks, @KarthikNedunchezhiyan!
Added
- M1 Mac support by bumping the ring dependency. Thanks, @ryanmcgrath!
- Breaking (sort of): the redirection code was improved to match
RFC 7231 section
7.1.2, which
could subtly break some programs relying on very specific redirects,
which is why this should be investigated if you come across weird
behaviour after updating. No API changes though, so only a minor
version bump. The following two points are now fixed when
redirecting:
-
2.2.122 Aug 2020Release notes
Open source →Fixed
- Some documentation which has been long due for an update. I just always forget when writing an actual update. No code changes!
-
2.2.018 Jun 2020Release notes
Open source →Added
- Support for
native-tlsandopenssl-sysvia new features, in addition torustls. Thanks to @dubiousjim!
- Support for
-
2.1.130 Apr 2020 -
2.1.014 Mar 2020 -
2.0.315 Jan 2020Release notes
Open source →Fixed
- Fixed regression in header parsing caused by 2.0.2, which was yanked.
-
2.0.215 Jan 2020 withdrawnRelease notes
Open source →Fixed
- Fixed a panic when sending a request to an invalid domain via https.
- Fixed a panic when parsing headers that have >1 byte unicode characters right after the ":" in the response.
-
2.0.111 Jan 2020Release notes
Open source →Fixed
- Made timeouts work as described in the documentation. Fixed issue #22.
-
2.0.023 Nov 2019Release notes
Open source →Added
- API for loading the HTTP response body through an iterator, allowing
for processing of the data during the download.
- See the
ResponseLazydocumentation for more information.
- See the
- Error type for all the errors that this crate can run into for
easier
?usage and better debuggability. - Punycode support for non-ascii hostnames via the
punycodefeature. - Trailer header support.
- Examples
hello,iterator, andjson.
Changed
- Breaking, will cause problems not detectable by the compiler:
Response headers' field names are now in lowercase, as they are
case-insensitive and this makes getting header values easier. The
values are unaffected. So if your code has
response.headers.get("Content-Type"), you have to change it toresponse.headers.get("content-type"), or it will not return what you want. - Breaking: Restructure the
Responsestruct:- Removed
bytesandbody_bytes. - Added
as_bytes(),into_bytes(), andas_str()in their place.
- Removed
- Breaking: Changed the
with_bodyparameter type toInto<Vec<u8>>fromInto<String>.Strings implementInto<Vec<u8>>, so this shouldn't cause any problems, unless you're using some interesting types that implementInto<String>but notInto<Vec<u8>>.
- Clean up the crate internals overall. Note: This might cause instability, if you're very concerned about stability, please hold off upgrading for a while.
- Remove
panic!when trying to make anhttps://request without thehttpsfeature. The request will now return an error instead. The library should not panic anymore. - Audit the remaining
unwrap()s from library code, none of them should actually ever cause a panic now.
Removed
create_requestin favor of just usingResponse::new.
- API for loading the HTTP response body through an iterator, allowing
for processing of the data during the download.
-
2.0.0-alpha.229 Oct 2019 pre-releaseNothing published for this version
-
2.0.0-alpha.110 Oct 2019 pre-releaseNothing published for this version
-
1.4.113 Oct 2019Release notes
Open source →Changed
- Updated dependencies.
Fixed
- Tests on Windows by changing the ip in tests from
0.0.0.0tolocalhost. - Reuse
rustls::ClientConfigbetween requests. Content-LengthandTransfer-Encodingdetection failing because of case-sensitiveness.
-
1.4.013 Jul 2019 -
1.3.004 Jun 2019Release notes
Open source →Added
- The
body_bytesfield to Response, containing the body in raw bytes.
Fixed
- Some clippy warnings.
- Panic when getting a non-UTF-8 response, instead setting the
bodystring to an empty string, for now.
- The
-
1.2.124 May 2019 -
1.2.023 May 2019Release notes
Open source →Added
- Support for the HTTP status codes 301, 302, 303, and 307.
Fixed
- Less .clones()s.
-
1.1.214 Apr 2019 -
1.1.128 Mar 2019Release notes
Open source →Changed
- Moved to 2018 edition.
Fixed
- HEAD requests and ones that receive a 1xx, 204, or 304 status code as a response.
-
1.1.024 Mar 2019Release notes
Open source →Changed
- Timeout made optional.
- Updated dependencies.
Fixed
- Improved performance for HTTP (not HTTPS) requests.
-
1.0.424 Mar 2019 withdrawnNothing published for this version
-
1.0.330 Jul 2018Nothing published for this version
-
1.0.218 Mar 2018Nothing published for this version
-
1.0.118 Mar 2018Nothing published for this version
-
0.1.218 Mar 2018Nothing published for this version
-
0.1.018 Mar 2018Nothing published for this version