NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #7 most downloaded on PyPI
Python HTTP for Humans.
Last release 4 months ago
14 May 2026
Release timing varies
gaps range from 8 days to 13 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
2 versions withdrawn
withdrawn after publishing
16 years old
163 releases · first in 2011
SOCKS Proxy Support! (requires PySocks; $ pip install requests[socks])
New Features
$ pip install requests[socks])Miscellaneous
Change built-in CaseInsensitiveDict (used for headers) to use OrderedDict as its underlying datastore.
Improvements
Bugfixes
tell(), send them
via chunked transfer encoding instead of failing.One column per quarter.
Resolve regression introduced in 2.9.0 that made it impossible to send binary strings as bodies in Python 3.
Bugfixes
Miscellaneous
Minor Improvements (Backwards compatible)
Minor Improvements (Backwards compatible)
verify keyword argument now supports being passed a path to a
directory of CA certificates, not just a single-file bundle.Bugfixes
Transfer-Encoding: chunked rather
than Content-Length: 0.qop
directive that contains no token, by treating it the same as if no
qop directive was provided at all.Miscellaneous
Update certificate bundle to match certifi 2015.9.6.2's weak certificate bundle.
Bugfixes
certifi 2015.9.6.2's weak
certificate bundle.ConnectTimeout
instead of ConnectionErrorjson parameter. Broken in 2.8.0.Minor Improvements (Backwards Compatible)
Minor Improvements (Backwards Compatible)
proxies
dictionary to have entries of the form
{'<scheme>://<hostname>': '<proxy>'}. Host-specific proxies will
be used in preference to the previously-supported scheme-specific
ones, but the previous syntax will continue to work.Response.raise_for_status now prints the URL that failed as part
of the exception message.requests.utils.get_netrc_auth now takes an raise_errors kwarg,
defaulting to False. When True, errors parsing .netrc files
cause exceptions to be thrown.Bugfixes
json parameter to post() and friends will now only be used
if neither data nor files are present, consistent with the
documentation.NO_PROXY environment variable.httplib.BadStatusLine would get raised if
combining stream=True with contextlib.closing.Updates
This is the first release that follows our new release process. For more, see our documentation.
This is the first release that follows our new release process. For more, see our documentation.
Bugfixes
Fix regression where compressed data that was sent as chunked data was not properly decompressed. (\#2561)
Bugfixes
Remove VendorAlias import machinery introduced in v2.5.2.
Bugfixes
CVE-2015-2296: Fix handling of cookies on redirect. Previously a cookie without a host value set would use the hostname for the redirected URL exposin…
Bugfixes
install_requires dependency and
python setup.py test is run. (#2462)urllib3's header handling.Features and Improvements
files
argument. (#2468)str, bytes,
or bytearray input to the files argument.Revert changes to our vendored certificate bundle. For more context see (\#2455, \#2456, and )
Bugfixes
Add sha256 fingerprint support. (shazow/urllib3\#540)
Features and Improvements
Bugfixes
Set-Cookie headers properly.
(shazow/urllib3#534)Security
cacert.pem.Only catch HTTPErrors in raise\_for\_status (\#2382)
Behavioural Changes
Bugfixes
Add deprecation warnings to functions in requests.utils that will be removed in 3.0 (\#2309)
Improvements
iter_lines method on a response now accepts a delimiter with
which to split the content (#2295)Behavioural Changes
Bugfixes
Documentation
Unicode URL improvements for Python 2.
Bugfixes
FINALLY! Add json parameter for uploads! (\#2258)
Now has a "security" package extras set, $ pip install requests[security]
$ pip install requests[security]Connection: keep-alive header is now sent automatically.
Behavioral Changes
Connection: keep-alive header is now sent automatically.Improvements
No longer expose Authorization or Proxy-Authorization headers on redirect. Fix CVE-2014-1829 and CVE-2014-1830 respectively.
API Changes
Response property is_redirect, which is true when the
library could have processed this response as a redirection (whether
or not it actually did).timeout parameter now affects requests with both stream=True
and stream=False equally.http://.CaseInsensitiveDict used for HTTP headers now behaves like a
normal dictionary when references as string or viewed in the
interpreter.Bugfixes
None on the Session are now correctly not sent.decode_unicode even if it wasn't used earlier in
the same response.compress as a supported Content-Encoding.Response.history parameter is now always a list.urllib3 bugfixes.Fixes incorrect parsing of proxy credentials that contain a literal or encoded '\#' character.
Bugfixes
New exception: ContentDecodingError. Raised instead of urllib3 DecodeError exceptions.
API Changes
ContentDecodingError. Raised instead of urllib3
DecodeError exceptions.Bugfixes
proxy_bypass on OS X in Python 2.6.CookieJar objects.Cookies set on individual Requests through a Session (e.g. via Session.get()) are no longer persisted to the Session.
Session (e.g. via
Session.get()) are no longer persisted to the Session.Host:
header.Response objects pickleable.Updated included CA Bundle with new mistrusts and automated process for the future
Keys in the Headers dictionary are now native strings on all Python versions, i.e. bytestrings on Python 2, unicode on Python 3.
API Changes:
MissingSchema
exception will be raised if they don't.Stream=False.RequestException is now a subclass of IOError, not
RuntimeError.PreparedRequest objects:
PreparedRequest.copy().Session objects: Session.update_request().
This method updates a Request object with the data (e.g. cookies)
stored on the Session.Session objects: Session.prepare_request().
This method updates and prepares a Request object, and returns the
corresponding PreparedRequest object.HTTPAdapter objects:
HTTPAdapter.proxy_headers(). This should not be called directly,
but improves the subclass interface.httplib.IncompleteRead exceptions caused by incorrect chunked
encoding will now raise a Requests ChunkedEncodingError instead.InvalidURL
exception to be raised."im_used". Correctly uses
"already_reported"."im_used").Bugfixes:
.netrc no longer overrides explicit auth.BytesIO can be used to perform streaming uploads.no_proxy environment variable.- Simple packaging fix
- Simple packaging fix
301 and 302 redirects now change the verb to GET for all verbs, not just POST, improving browser compatibility.
Fixed cookies on sessions and on requests
signature_type sent no
datajson.loads() via the
Response.json() methodContent-Length header by default on GET or HEAD
requestselapsed attribute to Response objects to time how long a
request took.RequestsCookieJarThe change in how hooks are dispatched will likely cause a great deal of issues.
Support for iterable response bodies
Nothing published for this version
- Fix file upload encoding bug - Fix cookie behavior
- Proxy fix for HTTPAdapter.
Cert verification exception bug.
Massive Refactor and Simplification
This is not a backwards compatible change.
Improved mime-compatible JSON handling
- Python 3.3 Compatibility - Simply default accept-encoding - Bugfixes
No more iter\_content errors if already downloaded.
Remove exception eating from dispatch\_hook
Incredible Link header support :)
Support for (key, value) lists everywhere.
Long awaited fix for hanging connections!
- Packaging fix
GSSAPI/Kerberos authentication!
Do not hide SSLErrors behind Timeouts.
Zero dependencies (once again)!
Allow passing a file or file-like object as data.
Removal of Requests.async in favor of grequests
Nothing published for this version
Ability to add string file uploads.
Response.json property.Proper CookieJar-backed cookies interface with awesome dict-like interface.
pre_request to a more usable place.pre_send hook.certify isn't available.Attempt to use the OS's certificate bundle if certifi isn't available.
certifi isn't
available.POST redirects now break RFC to do what browsers do: Follow up with a GET.
strict_mode configuration to disable new redirect behavior.Generate chunked ValueError fix
- encode\_uri = False
- Allow '=' in cookies.
- Honor netrc.
HEAD requests don't follow redirects anymore.
Additional allowed cookie key values.
Dropped 2.5 Support. (*Backwards Incompatible*)
Response.content is now bytes-only. (*Backwards Incompatible*)
Response.content is now bytes-only. (Backwards Incompatible)Response.text is unicode-only.Response.encoding is specified and chardet is available,
Response.text will guess an encoding.Response.register_hook for registering hooks within the
pipeline.Response.url is now Unicode.Your coding agent can read these notes before it upgrades. Set up the MCP server →