HTTP semanticseasy0-2 years
What's the difference between a safe HTTP method and an idempotent one, and why does POST need special handling that PUT doesn't?
Safe means the method doesn't change server state — GET and HEAD. Idempotent means repeating the request N times leaves the server in the same state as doing it once — GET, HEAD, PUT and DELETE are idempotent, POST is not. PUT is idempotent because it means "store exactly this representation at this URI": sending the same body twice can only produce the same stored state. POST has no such definition — the server decides what happens, so a client that retries a timed-out POST (an order, a charge) has no way to know whether the first one landed, and a naive retry creates a second one.