Two properties from RFC 9110 decide how clients, proxies and caches treat a method. A safe method is read-only, so crawlers may call it freely. An idempotent one has the same effect whether it runs once or ten times, so a client may retry it: PUT /users/7 repeated leaves the same user, POST /orders repeated creates two orders.
| Method | Purpose | Safe | Idempotent | Body |
|---|---|---|---|---|
| GET, HEAD | Read; headers only | Yes | Yes | No |
| QUERY | Read, query in body | Yes | Yes | Yes |
| POST | Create or process | No | No | Yes |
| PUT | Replace a resource | No | Yes | Yes |
| PATCH | Modify part of it | No | No | Yes |
| DELETE | Remove a resource | No | Yes | Rarely |
| OPTIONS | Ask what is allowed | Yes | Yes | Rarely |
| CONNECT, TRACE | Tunnel; echo test | No, Yes | No, Yes | No |
QUERY, defined by RFC 10008 in June 2026, is a safe, cacheable request that carries its query in the body, for searches too long for a URL; check your framework, proxy and CDN before relying on it. An HTML <form> sends only GET or POST, while fetch() sends anything except the forbidden CONNECT, TRACE and TRACK. A cross-origin PUT, PATCH or DELETE first triggers an OPTIONS preflight (crossorigin).