Skip to content
Glossary

HTTP CONNECT

The HTTP method that asks a proxy to open a raw tunnel, which is how HTTPS travels through an HTTP proxy.

CONNECT asks a proxy to establish a TCP tunnel to a destination and then relay bytes without interpreting them. It is the mechanism that lets encrypted HTTPS traffic pass through a proxy that otherwise speaks HTTP.

#The exchange

CONNECT api.example.com:443 HTTP/1.1
Host: api.example.com:443
Proxy-Authorization: Basic dXNlcjpwYXNz

HTTP/1.1 200 Connection established

After the 200, the TLS handshake happens end to end between your client and the destination. The proxy relays ciphertext.

#What the proxy can and cannot see

  • Can see: the destination hostname and port, connection timing, and the volume of bytes transferred.
  • Cannot see: the URL path, headers, request body or response body.

This is why an HTTPS request through a proxy is far more private than a plain HTTP one — and why a proxy provider can still report which domains you contacted.

#Reference

CONNECT is defined in RFC 9110, which specifies current HTTP semantics.

#Reading a CONNECT exchange

The method is defined in RFC 9110. The client asks for a tunnel to a host and port, and the proxy answers before any TLS begins.

CONNECT api.example.com:443 HTTP/1.1
Host: api.example.com:443
Proxy-Authorization: Basic dXNlcjpwYXNz

HTTP/1.1 200 Connection established

After the 200 the proxy copies bytes in both directions without interpreting them. The TLS handshake that follows is between your client and the destination, so the proxy cannot read it.

#What the proxy still learns

Visible to the proxy Hidden from the proxy
The destination hostname and port The request path and query
Byte counts in each direction Request and response headers
Connection timing and duration The response body
Your own address and credentials Cookies and authorisation tokens

The left column is enough to build a full record of which sites you visit and how much you transfer. Encryption protects the contents, not the pattern.

#Common responses

  • 200 — the tunnel is open.
  • 407 — credentials are missing or wrong. See proxy authentication.
  • 403 — the proxy refuses this destination by policy.
  • 502 or 504 — the proxy could not reach the destination.

Frequently asked questions

Why does HTTPS through a proxy need a special method?
Because the proxy cannot read an encrypted request to learn where to send it. CONNECT tells the proxy the destination in plain text first, so it can open a raw tunnel and then step out of the way.
Can a proxy see my HTTPS traffic after CONNECT?
Not the contents. It sees the destination hostname and port, the timing and the byte counts. Reading the contents would require the proxy to terminate TLS itself, which changes the certificate your client receives and is therefore detectable.
What does a 407 during CONNECT mean?
The proxy requires authentication and your credentials were absent or rejected. It is a proxy-side status, not a destination-side one, so the destination was never contacted.

Sources

  1. RFC 9110: HTTP Semantics, section 9.3.6, the CONNECT method

Related terms