HTTP CONNECT
The HTTP method that asks a proxy to open a raw tunnel, which is how HTTPS travels through an HTTP proxy.
CONNECT asks a proxy to establish a TCP tunnel to a destination and then relay bytes without interpreting them. It is the mechanism that lets encrypted HTTPS traffic pass through a proxy that otherwise speaks HTTP.
#The exchange
CONNECT api.example.com:443 HTTP/1.1
Host: api.example.com:443
Proxy-Authorization: Basic dXNlcjpwYXNz
HTTP/1.1 200 Connection established
After the 200, the TLS handshake happens end to end between your client and the destination. The proxy relays ciphertext.
#What the proxy can and cannot see
- Can see: the destination hostname and port, connection timing, and the volume of bytes transferred.
- Cannot see: the URL path, headers, request body or response body.
This is why an HTTPS request through a proxy is far more private than a plain HTTP one — and why a proxy provider can still report which domains you contacted.
#Reference
CONNECT is defined in RFC 9110, which specifies current HTTP semantics.
#Reading a CONNECT exchange
The method is defined in RFC 9110. The client asks for a tunnel to a host and port, and the proxy answers before any TLS begins.
CONNECT api.example.com:443 HTTP/1.1
Host: api.example.com:443
Proxy-Authorization: Basic dXNlcjpwYXNz
HTTP/1.1 200 Connection established
After the 200 the proxy copies bytes in both directions without interpreting them. The TLS handshake that follows is between your client and the destination, so the proxy cannot read it.
#What the proxy still learns
| Visible to the proxy | Hidden from the proxy |
|---|---|
| The destination hostname and port | The request path and query |
| Byte counts in each direction | Request and response headers |
| Connection timing and duration | The response body |
| Your own address and credentials | Cookies and authorisation tokens |
The left column is enough to build a full record of which sites you visit and how much you transfer. Encryption protects the contents, not the pattern.
#Common responses
- 200 — the tunnel is open.
- 407 — credentials are missing or wrong. See proxy authentication.
- 403 — the proxy refuses this destination by policy.
- 502 or 504 — the proxy could not reach the destination.