NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Maven Central
Square’s meticulous HTTP client for Java and Kotlin.
Last release 3 years ago
no release in 18 months
Release timing varies
gaps range from 3 weeks to 12 months
Unknown
no stable releases
Nothing withdrawn
no release was ever pulled
5 years old
7 releases · first in 2022
One column per quarter.
We took too long to cut this release and there's a lot of changes in it. We've been busy.
2023-12-17
We took too long to cut this release and there's a lot of changes in it. We've been busy.
Although this release is labeled alpha, the only unstable thing in it is our new APIs. This release has many critical bug fixes and is safe to run in production. We're eager to stabilize our new APIs so we can get out of alpha.
New: Support Java 21's virtual threads (‘OpenJDK Project Loom’). We changed OkHttp's internals
to use Lock and Condition instead of synchronized for best resource utilization.
New: Switch our Internationalized Domain Name (IDN) implementation to [UTS #46 Nontransitional
Processing][uts46]. With this fix, the ß code point no longer maps to ss. OkHttp now embeds
its own IDN mapping table in the library.
New: Prefer the client's configured precedence order for TLS cipher suites. (OkHttp used to prefer the JDK’s precedence order.) This change may cause your HTTP calls to negotiate a different cipher suite than before! OkHttp's defaults cipher suites are selected for good security and performance.
New: ConnectionListener publishes events for connects, disconnects, and use of pooled
connections.
Fix: Immediately update the connection's flow control window instead of waiting for the receiving stream to process it.
This change may increase OkHttp's memory use for applications that make many concurrent HTTP calls and that can receive data faster than they can process it. Previously, OkHttp limited HTTP/2 to 16 MiB of unacknowledged data per connection. With this fix there is a limit of 16 MiB of unacknowledged data per stream and no per-connection limit.
Fix: Don't close a Deflater while we're still using it to compress a web socket message. We
had a severe bug where web sockets were closed on the wrong thread, which caused
NullPointerException crashes in Deflater.
Fix: Don't crash after a web socket fails its connection upgrade. We incorrectly released the web socket's connections back to the pool before their resources were cleaned up.
Fix: Don't infinite loop when a received web socket message has self-terminating compressed data.
Fix: Don't fail the call when the response code is ‘HTTP 102 Processing’ or ‘HTTP 103 Early Hints’.
Fix: Honor interceptors' changes to connect and read timeouts.
Fix: Recover gracefully when a cached response is corrupted on disk.
Fix: Don't leak file handles when a cache disk write fails.
Fix: Don't hang when the public suffix database cannot be loaded. We had a bug where a failure reading the public suffix database would cause subsequent reads to hang when they should have crashed.
Fix: Avoid InetAddress.getCanonicalHostName() in MockWebServer. This avoids problems if the
host machine's IP address has additional DNS registrations.
New: Create a JPMS-compatible artifact for JavaNetCookieJar. Previously, multiple OkHttp
artifacts defined classes in the okhttp3 package, but this is forbidden by the Java module
system. We've fixed this with a new package (okhttp3.java.net.cookiejar) and a new artifact,
com.squareup.okhttp3:okhttp-java-net-cookiehandler. (The original artifact now delegates to
this new one.)
implementation("com.squareup.okhttp3:okhttp-java-net-cookiehandler:5.0.0-alpha.12")
New: Cookie.sameSite determines whether cookies should be sent on cross-site requests. This
is used by servers to defend against Cross-Site Request Forgery (CSRF) attacks.
New: Log the total time of the HTTP call in HttpLoggingInterceptor.
New: OkHttpClient.Builder now has APIs that use kotlin.time.Duration.
New: mockwebserver3.SocketPolicy is now a sealed interface. This is one of several
backwards-incompatible API changes that may impact early adopters of this alpha API.
New: mockwebserver3.Stream for duplex streams.
New: mockwebserver3.MockResponseBody for streamed response bodies.
New: mockwebserver3.MockResponse is now immutable, with a Builder.
New: mockwebserver3.RecordedRequest.handshakeServerNames returns the SNI (Server Name
Indication) attribute from the TLS handshake.
Upgrade: [Kotlin 1.9.21][kotlin_1_9_21].
Upgrade: [Okio 3.7.0][okio_3_7_0].
New: Enable fast fallback by default. It's our implementation of Happy Eyeballs, [RFC 8305][rfc_8305]. Disable with OkHttpClient.Builder.fastFallback(
2022-12-24
OkHttpClient.Builder.fastFallback(false).Request.toString().ExecutorService is shutdown with many
calls still enqueued.Fix: Configure the multiplatform artifact (com.squareup.okhttp33.x.x) to depend on the JVM artifact (com.squareup.okhttp3:okhttp-jvm:3.x.x) for Maven
2022-06-26
com.squareup.okhttp3:okhttp:3.x.x) to depend on the
JVM artifact (com.squareup.okhttp3:okhttp-jvm:3.x.x) for Maven builds. This should work-around
an issue where Maven doesn't interpret Gradle metadata.DurationUnit which was a typealias in 1.5.x.New: Enforce label length limits in URLs. HttpUrl now rejects URLs whose domains aren't valid. This includes overly-long domain names (longer than 253
2022-06-16
HttpUrl now rejects URLs whose domains aren't valid.
This includes overly-long domain names (longer than 253 characters), overly-long labels (more
than 63 characters between dots), and empty labels.Content-Length header in multipart bodies. Servers must delimit
OkHttp's request bodies using the boundary only. (This change makes OkHttp more consistent with
browsers and other HTTP clients.)tunnelProxy argument in MockWebServer.useHttps(). This change only impacts
the OkHttp 5.x API which uses the mockwebserver3 package.toDuration() which isn't available in kotlin-stdlib 1.4.Fix: Change how H2_PRIOR_KNOWLEDGE works with HTTP proxies. Previously OkHttp assumed the proxy itself was a prior knowledge HTTP/2 server. With this
2022-06-08
Fix: Change how H2_PRIOR_KNOWLEDGE works with HTTP proxies. Previously OkHttp assumed the
proxy itself was a prior knowledge HTTP/2 server. With this update, OkHttp attempts a CONNECT
tunnel just as it would with HTTPS. For prior knowledge with proxies OkHttp's is now consistent
with these curl arguments:
curl \
--http2-prior-knowledge \
--proxy localhost:8888 \
--proxytunnel \
http://squareup.com/robots.txt
Fix: Support executing OkHttp on kotlin-stdlib versions as old as 1.4. The library still builds on up-to-date Kotlin releases (1.6.21) but no longer needs that version as a runtime dependency. This should make it easier to use OkHttp in Gradle plugins.
Fix: Don't start the clock on response timeouts until the request body is fully transmitted. This is only relevant for duplex request bodies, because they are written concurrently when reading the response body.
New: MockResponse.inTunnel() is a new mockwebserver3 API to configure responses that are
served while creating a proxy tunnel. This obsoletes both the tunnelProxy argument on
MockWebServer and the UPGRADE_TO_SSL_AT_END socket option. (Only APIs on mockwebserver3
are changed; the old okhttp3.mockwebserver APIs remain as they always have been.
This release introduces new Kotlin-friendly APIs. When we migrated OkHttp from Java to Kotlin in OkHttp 4.0, we kept our Java-first APIs. With 5.0 we'
2022-04-26
This release introduces new Kotlin-friendly APIs. When we migrated OkHttp from Java to Kotlin in
OkHttp 4.0, we kept our Java-first APIs. With 5.0 we're continuing to support Java and adding
additional improvements for Kotlin users. In this alpha we're excited to skip-the-builder for
requests and remove a common source of non-null assertions (!!) on the response body.
The alpha releases in the 5.0.0 series have production-quality code and an unstable API. We expect to make changes to the APIs introduced in 5.0.0-alpha.X. These releases are safe for production use and 'alpha' strictly signals that we're still experimenting with some new APIs. If you're eager for the fixes or features below, please upgrade.
New: Named and default parameters constructor for Request:
val request = Request(
url = "https://cash.app/".toHttpUrl(),
)
New: Response.body is now non-null. This was generally the case in OkHttp 4.x, but the Kotlin
type declaration was nullable to support rare cases like the body on Response.cacheResponse,
Response.networkResponse, and Response.priorResponse. In such cases the body is now
non-null, but attempts to read its content will fail.
New: Kotlin-specific APIs for request tags. Kotlin language users can lookup tags with a type
parameter only, like request.tag<MyTagClass>().
New: MockWebServer has improved support for HTTP/1xx responses. Once you've migrated to the new
mockwebserver3 package, there's a new field, MockResponse.informationalResponses.
Fix: Don't interpret trailers as headers after an HTTP/100 response. This was a bug only when the HTTP response body itself is empty.
Fix: Don't crash when a fast fallback call has both a deferred connection and a held connection.
Fix: OkHttpClient no longer implements Cloneable. It never should have; the class is
immutable. This is left over from OkHttp 2.x (!) when that class was mutable. We're using the
5.x upgrade as an opportunity to remove very obsolete APIs.
Fix: Recover gracefully when Android's NativeCrypto crashes with "ssl == null". This occurs
when OkHttp retrieves ALPN state on a closed connection.
Upgrade: [Kotlin 1.6.21][kotlin_1_6_21].
Upgrade: [Okio 3.1.0][okio_3_1_0].
Fix: Don't attempt to close pooled connections. We saw occasional fast fallback calls crash in the previous alpha due to an unexpected race.
2022-03-14
Your coding agent can read these notes before it upgrades. Set up the MCP server →