Glossary · Automation fundamentals, platforms and components
Hypertext Transfer Protocol (HTTP)
Also known as: HTTP, HTTPS
German: HTTP
In networking, the Hypertext Transfer Protocol (HTTP) is an application-layer request/response protocol used by web browsers, web servers and APIs. HTTPS is HTTP secured with TLS. Its semantics are specified in RFC 9110.
- Automation components
- Standards
In one sentence
HTTP is the request/response protocol of the web and of REST APIs; HTTPS adds TLS encryption. Its semantics are specified in RFC 9110.
Example
A device's integrated web server lets technicians read diagnostics over HTTPS, and an MES reads production counters via a REST API.
How it applies
- Engineering: Many devices offer web servers for configuration and diagnostics, and IT integration often uses REST APIs over HTTP with JSON payloads.
- Security: Plain HTTP is unencrypted; use HTTPS, disable unused web servers and change default credentials.
- Documentation: Describe which ports are open, whether HTTP or HTTPS is used, how certificates are handled and how to disable the web server. For APIs, document endpoints, methods, status codes and payload schemas.
- Operation: Firewalls between IT and OT networks should only open the HTTP or HTTPS ports that are actually needed.
HTTP vs. MQTT
HTTP is request/response: the client asks and the server answers. MQTT is publish/subscribe via a broker and suits frequent, small messages from many devices. The choice affects network load, latency and security design.