lysine-dev/okhttp
53.7
Weak · 25 September 2026
58.1k
lines of production code
Kotlin
with Java
3
measurements over time
What this system is
This system is OkHttp, a high-performance HTTP and HTTP/2 client library designed for Android and Java applications. It provides a comprehensive suite of networking capabilities, including transparent compression via Brotli and Zstandard, secure TLS handling with certificate pinning, and support for advanced protocols like DNS-over-HTTPS and Server-Sent Events. The library also includes a robust testing framework, MockWebServer, for simulating server interactions, alongside utilities for logging, cookie management, and native image compilation.
How it got here
2012–2020 — Modernization and testing expansion
47 changes.
The project overhauled its build infrastructure to modern Gradle conventions while significantly expanding sample applications and documentation for both Java and Kotlin. Concurrently, it introduced new features like Brotli compression and Encrypted Client Hello support, alongside a major restructuring of the MockWebServer testing library and extensive additions to TLS and platform-specific test coverage.
2021–2023 — API stabilization and native image support
33 changes.
This period focused on formalizing public API contracts across multiple OkHttp modules using binary compatibility validators, while introducing GraalVM native-image support and Brotli compression. Significant efforts were also made to modernize the testing infrastructure, including the definition of the MockWebServer3 API, JUnit 5 integration, and extensive test coverage for Android, DNS-over-HTTPS, and HTTP/2 behaviors.
2024–2026 — Kotlin migration and modularization
39 changes.
This period focused on migrating core OkHttp classes to Kotlin and splitting the public API into platform-specific variants for Android and JVM. The work included adding Java Platform Module System (JPMS) support, introducing Zstandard compression, and implementing automatic Android initialization via AndroidX Startup. Extensive test coverage was added across JVM, Android, and native-image environments, alongside infrastructure upgrades like JUnit 5 migration and Gradle convention plugin decoupling.
Features
Add Crawler sample application
A new sample application, Crawler.java, has been added to the samples/crawler directory. This tool demonstrates how to use OkHttpClient with a cache and call timeouts to fetch HTML content, parse links using Jsoup, and follow them in a multi-threaded manner while respecting host limits and queue sizes.
samples/crawler · high confidence
Add HttpLoggingInterceptor and LoggingEventListener for detailed HTTP debugging
The okhttp-logging-interceptor module now provides two new components for debugging HTTP traffic: HttpLoggingInterceptor, which logs request and response lines, headers, and bodies with configurable redaction of sensitive query parameters, and LoggingEventListener, which logs granular lifecycle events such as DNS resolution, connection establishment, and dispatcher queue status. These additions allow users to gain deeper visibility into the internal state and timing of OkHttp calls beyond basic request/response logging.
okhttp-logging-interceptor/src/main/kotlin · high confidence
Add JUnit 4 integration rule for MockWebServer
Users can now integrate MockWebServer into JUnit 4 tests using the new \MockWebServerRule\. This rule, available in the \mockwebserver3.junit4\ module, automatically starts the mock server before each test and closes it afterward, simplifying test setup for Java and Kotlin projects using JUnit 4. The module also includes a Java 9 module descriptor to support Java Modules.
mockwebserver-junit4/src/main · high confidence
Add Maven-based test module with Maven Wrapper 3.3.4 and Maven 4.0.0-rc-6
A new Maven test module has been added to the project, including the Maven Wrapper (mvnw) scripts and configuration files. The wrapper is configured to use Maven Wrapper version 3.3.4 and downloads Apache Maven version 4.0.0-rc-6. The module contains a sample HTTP client implementation using OkHttp and a corresponding JUnit test that validates the client against a MockWebServer, ensuring the build environment and dependencies function correctly.
maven-tests · high confidence
Add OkHttpContributors sample using Moshi for JSON parsing
A new sample application, OkHttpContributors, has been added to the simple-client module. This example demonstrates fetching GitHub repository contributors via the API and deserializing the JSON response into Java objects using Moshi, replacing previous manual parsing approaches.
samples/simple-client · high confidence
Add Slack API sample application
Introduces a new sample application in the \samples/slack\ directory that demonstrates using OkHttp to interact with the Slack API. The sample includes an \SlackApi\ class for handling REST calls and OAuth token exchange, an \OAuthSessionFactory\ that runs a local MockWebServer to simulate the OAuth callback flow, and an \RtmSession\ class that establishes a real-time messaging WebSocket connection. It also provides a \SlackClient\ entry point that orchestrates the OAuth authorization and RTM session startup.
samples/slack · high confidence
Add UNIX domain socket sample implementation
The unixdomainsockets sample now includes the core factory classes (UnixDomainServerSocketFactory and UnixDomainSocketFactory) that impersonate standard TCP-style ServerSocketFactory and SocketFactory over UNIX domain sockets, enabling users to see how to integrate UNIX socket transport with OkHttp.
unixdomainsockets · high confidence
Add Zstandard (zstd) compression support
OkHttp now supports the Zstandard (zstd) compression algorithm. Users can enable automatic decompression of zstd-encoded HTTP responses by including the \okhttp-zstd\ module and passing the \Zstd\ singleton to the \CompressionInterceptor\. This allows clients to benefit from zstd's compression ratio and speed alongside existing gzip and brotli support.
okhttp-zstd/src · high confidence
Add android-test-app to verify multi-process and ProGuard behavior
The android-test-app module has been added to provide an end-to-end verification environment for OkHttp on Android. It includes a TestApplication that initializes OkHttp in secondary processes, ensuring multi-process support works correctly, and a MainActivity that exercises URL parsing and network calls. The app is configured with a network security policy disabling cleartext traffic and includes ProGuard rules to prevent the removal of the IDNA mapping table, which is validated by new instrumentation tests for IDNA hostname handling and public suffix database lookups.
android-test-app · high confidence
Add fuzzing test infrastructure for WebSocket server compliance
Added a new fuzzing test suite in the fuzzing directory to validate the WebSocket server against the Autobahn\|TS test suite. This includes a configuration file (fuzzingserver-config.json) that defines the test cases to run and exclude, an expected results file (fuzzingserver-expected.txt) documenting the baseline behavior for various protocol sections, and shell scripts (fuzzingserver-test.sh and fuzzingserver-update-expected.sh) to execute the tests against a local server instance and update the expected results. This allows developers to verify that the server's WebSocket implementation conforms to the RFC 6455 specification and handles edge cases correctly.
fuzzing · high confidence
Added GraalVM Native Image support for OkHttp
OkHttp now includes built-in configuration for GraalVM Native Image builds. The new \OkHttpFeature\ class automatically registers necessary resources during the native image build process, while \GraalSvm\ provides specific substitutions to exclude unsupported TLS platforms (such as Bouncy Castle, Conscrypt, and OpenJSSE) and ensures the JDK 9 platform is used by default, allowing OkHttp to function correctly in native executables.
okhttp/src/jvmMain/kotlin/okhttp3/internal/graal · high confidence
Added GraalVM native-image configuration for OkHttp
OkHttp now includes native-image configuration files (native-image.properties, reflect-config.json, and resource-config.json) to support building with GraalVM. These additions enable HTTP/HTTPS support, register necessary Kotlin reflection metadata, and ensure the PublicSuffixDatabase resource is included in the native binary, allowing OkHttp to function correctly in native-image environments.
okhttp/src/jvmMain/resources · high confidence
Added HTTP GET and POST sample code
The guide samples now include Java examples demonstrating how to perform HTTP GET and POST requests using the OkHttpClient. The new GetExample and PostExample files show users how to construct requests, execute them, and handle response bodies, including a specific example for posting JSON data.
samples/guide/src/main/java/okhttp3/guide · high confidence
Added Java 9+ module descriptors to OkHttp components
This change introduces \module-info.java\ files across multiple OkHttp modules (including core, mockwebserver, logging interceptor, TLS, SSE, DNS-over-HTTPS, Brotli, and URL connection) to support the Java Platform Module System (JPMS). By defining explicit module names and dependencies, these components are now properly structured as Java modules, enabling better encapsulation and compatibility with modern Java applications that rely on the module path.
(repo-wide) · high confidence
Added build configuration utility properties
A new Kotlin utility file (OkHttpBuildUtils.kt) was added to the build-logic module to expose project-level properties for build configuration. This includes defaults for the target platform (jdk9), test Java version (21), Android build flag, and ALPN boot version, allowing these settings to be easily overridden via Gradle properties.
build-logic/src/main/kotlin/okhttp3 · high confidence
Expose OkHttp version constant on JVM
The JVM-specific implementation of the OkHttp object now exposes the library's version string via a public \VERSION\ field, allowing applications to programmatically retrieve the current OkHttp version at runtime.
okhttp/src/jvmMain/kotlin/okhttp3 · high confidence
Initial repository structure and documentation site setup
The repository is initialized with standard project configuration files including .editorconfig, .gitattributes, and .gitignore, alongside a .gitmodules file for the hpack-test-case submodule. A comprehensive CHANGELOG.md is added, documenting the history from version 1.0.2 through 5.5.0, including the new opt-in Encrypted Client Hello (ECH) support in 5.5.0 and various dependency upgrades. The project includes a README.md detailing usage, requirements (Android 5.0+/Java 8+), and Maven coordinates, as well as a CONTRIBUTING.md file establishing a strict policy against LLM-generated contributions. A MkDocs-based documentation site is configured via mkdocs.yml and deployment scripts (deploy\_website.sh, test\_docs.sh), with the LICENSE.txt file adopting the Apache License 2.0.
(repo-wide) · high confidence
Introduce Brotli compression support
This change adds a new Brotli compression implementation to the library, exposing the \okhttp3.brotli.Brotli\ class for decompression and the \okhttp3.brotli.BrotliInterceptor\ singleton for integration. These components implement the existing \CompressionInterceptor\ interface, allowing users to enable Brotli encoding/decoding alongside other supported algorithms.
okhttp-brotli/api · high confidence
Introduce OkCurl as a GraalVM-native curl clone for testing OkHttp
OkCurl is now available as a shell script that builds and runs a native image of an OkHttp-backed curl clone, allowing users to test OkHttp's HTTP engine (including HTTP/2) against web servers. The tool requires GraalVM to be installed and the GRAALVM\_HOME environment variable to be set, and can be executed locally via the provided shell script which triggers the native build and runs the resulting binary.
okcurl · high confidence
Introduce mockwebserver3 package with new public API surface
The mock web server library has been restructured into a new \mockwebserver3\ package, introducing a redesigned public API for scripting server behavior. Users can now configure responses using a new \MockResponse\ class with a Builder pattern, supporting features like HTTP/2 push promises, trailers, and granular socket effects (e.g., closing streams or stalling connections). Request handling is managed via a new \Dispatcher\ abstraction, with \QueueDispatcher\ serving as the default for sequential response playback. Incoming requests are captured in a new \RecordedRequest\ class that exposes detailed connection metadata, TLS handshake information, and body content as \ByteString\. The package also includes \MockResponseBody\ for custom body writers and \SocketHandler\ for duplex stream support, providing a more flexible and modern foundation for testing HTTP clients.
mockwebserver/src/main/kotlin · high confidence
Introduces internal DoH query implementation with response size limits
Adds the internal DnsOverHttpsQuery class and its Factory, which handles DNS-over-HTTPS requests by constructing HTTP calls for both POST and GET methods. The implementation includes logic to override queries for private or public hosts based on configuration and enforces a maximum response size limit (MAX\_RESPONSE\_SIZE) to prevent excessive memory usage during DNS resolution.
okhttp-dnsoverhttps/src/main/kotlin/okhttp3/dnsoverhttps/internal · high confidence
Introduction of the Okcurl command-line tool
The okcurl module now provides a new command-line utility that mimics curl's functionality using OkHttp. This tool allows users to execute HTTP requests with support for custom methods, headers, and POST data, while offering configurable timeouts for connection, reading, and the entire call. It includes options to follow redirects, bypass SSL certificate verification for insecure connections, and display protocol headers. Additionally, it features verbose logging modes that can output detailed HTTP/2 frames or SSL debug information to assist in troubleshooting network interactions.
okcurl/src/main/kotlin · high confidence
Java 9 module support for OkHttp
OkHttp now includes a module-info.java file, enabling it to be used as a Java Platform Module System (JPMS) module. This change defines the okhttp3 module, declares its dependencies on kotlin-stdlib, okio, and java.logging, and explicitly exports internal packages (such as internal.dns, internal.http, and internal.platform) to specific companion modules like okhttp3.dnsoverhttps, mockwebserver3, and okhttp3.logging, facilitating proper encapsulation and usage within modular Java applications.
okhttp/src/jvmMain/java9 · high confidence
Native image configuration for GraalVM
OkHttp now includes a native-image.properties file that configures GraalVM native image builds. This configuration enables HTTP and HTTPS protocols, adds support for all character sets, and registers the OkHttp-specific GraalVM feature to ensure proper runtime behavior in native images.
okhttp/src/main · high confidence
New @StartStop annotation for automatic MockWebServer lifecycle management in JUnit 5
Users can now annotate MockWebServer fields with @StartStop to have the server automatically started before tests and closed after tests. This new JUnit 5 extension supports both instance fields (started per test method) and static fields (started once per test class), and correctly handles @Nested test classes by ensuring servers in enclosing classes are also started. A module-info.java file is added to support Java Modules.
mockwebserver-junit5/api, mockwebserver-junit5/src · high confidence
New JavaNetCookieJar implementation for interoperability with java.net.CookieHandler
A new \JavaNetCookieJar\ class has been added to the \okhttp-java-net-cookiejar\ module, allowing OkHttp to delegate cookie storage and retrieval to the standard \java.net.CookieHandler\. This implementation bridges OkHttp's internal \Cookie\ objects with Java's native cookie handling by converting OkHttp cookies to \Set-Cookie\ headers for storage and parsing \Cookie\/\Cookie2\ request headers back into OkHttp cookies. The code includes specific logic to handle multiple cookies within a single header string and normalizes cookie values to prevent crashes during parsing.
okhttp-java-net-cookiejar/src/main/kotlin · high confidence
New Kotlin recipe samples for OkHttp documentation
Added a comprehensive set of Kotlin source files to the OkHttp guide samples directory, providing idiomatic examples for common HTTP tasks. These new recipes cover synchronous and asynchronous requests, header access, authentication, caching, call cancellation, certificate pinning, timeout configuration, per-call settings, and various POST methods (file, form, multipart, streaming, and string). The collection also includes advanced examples for tracking upload progress and performing client authentication using a Yubikey hardware key.
samples/guide/src/main/java/okhttp3/recipes/kt · high confidence
New LoggingFilesystem for Okio integration testing
A new LoggingFilesystem class has been added to the okhttp-testing-support module. This class extends ForwardingFileSystem to intercept and log all file system operations (such as reading, writing, deleting, and moving files) via println, providing a debugging tool for testing Okio-based file interactions.
okhttp-testing-support/src/main/kotlin/okhttp3/okio · high confidence
New OkHttp 3 recipe samples for common HTTP tasks
The samples/guide/src/main/java/okhttp3/recipes directory now includes a comprehensive set of Java examples demonstrating OkHttp 3 usage. These recipes cover fundamental operations such as synchronous and asynchronous GET requests, handling response headers, and managing HTTP caching. They also illustrate advanced configuration and security features, including setting per-call timeouts, configuring custom trust managers for HTTPS, implementing certificate pinning, and using interceptors for logging and request modification. Additional examples show how to post data (strings, files, forms, and multipart uploads), track download progress, cancel in-flight calls, and parse JSON responses using Moshi.
samples/guide/src/main/java/okhttp3/recipes · high confidence
New RecordingProxySelector test utility
A new RecordingProxySelector class has been added to the testing support library to help verify proxy selection behavior in tests. This utility records requested URIs and connection failures, allowing test cases to assert that the correct proxies were selected and to inspect details about connection failures.
okhttp-testing-support/src/main/kotlin/okhttp3/internal/http · high confidence
New TLS certificate utilities and builder classes
The okhttp-tls module introduces new Kotlin source files to handle TLS certificate operations. Certificates.kt adds extension functions to decode PEM-encoded certificates and encode X.509 certificates to PEM format. HandshakeCertificates.kt provides a builder pattern for configuring trusted root certificates, insecure hosts for development, and held certificates for client authentication, replacing previous implementations. HeldCertificate.kt defines a class to manage a certificate and its private key, supporting PKCS\#8 and PKCS\#1 private key encoding, and includes a builder for generating test certificates with custom validity periods and subject alternative names.
okhttp-tls/src/main/kotlin/okhttp3/tls · high confidence
New TLS cipher suite survey sample application
A new sample application in the tlssurvey module has been added to analyze and report on SSL/TLS cipher suite support across different clients. This tool fetches the current list of IANA TLS parameters, maps them to Java cipher suite names, and generates a formatted report (suitable for Google Sheets) showing which cipher suites are enabled and their precedence order for a given set of client configurations.
tlssurvey · high confidence
New TLS survey sample for comparing cipher suites across clients
The \samples/tlssurvey\ module has been added to help users compare TLS cipher suite support across different HTTP clients and Java versions. It queries the SSL Labs API to identify enabled suites for major browsers (Chrome, Firefox, Safari) and platforms (Android, iOS, macOS), and compares them against the current OkHttp version, historic OkHttp versions (3.9, 3.11, 3.13, 3.14, 4.10), the default JVM, and Conscrypt. The sample includes resource files defining cipher suites for each historic OkHttp version and Kotlin code to orchestrate the survey and output results to a Google Sheet.
samples/tlssurvey · high confidence
New TaskFaker and TaskRunnerTesting utilities for deterministic testing
The testing support library now includes a new TaskFaker class and TaskRunnerTesting extension functions. TaskFaker allows tests to run TaskRunner tasks in a controlled, sequential environment, ensuring deterministic execution by simulating time and managing task queues without concurrent thread interference. The new TaskRunnerTesting.kt file provides a convenient schedule extension for TaskRunner, enabling easier setup of delayed tasks in tests using Kotlin's Duration API.
okhttp-testing-support/src/main/kotlin/okhttp3/internal/concurrent · high confidence
New UNIX domain socket sample with HTTP/2 support
The samples/unixdomainsockets directory now includes a new example demonstrating how to use OkHttp with UNIX domain sockets. The ClientAndServer sample connects a MockWebServer and an OkHttp client over a UNIX socket, specifically configured to use HTTP/2 via H2\_PRIOR\_KNOWLEDGE. Additionally, a TunnelingUnixSocket class is introduced to provide a higher-fidelity impersonation of TCP sockets by mapping UNIX socket operations to standard TCP-like address interfaces.
samples/unixdomainsockets · high confidence
New build tooling for compact IDNA mapping table generation
A new module has been added to provide supporting tools for building the IDNA mapping table. This includes a Kotlin-based code generator that reads the raw Unicode IDNA mapping data (IdnaMappingTable.txt) and produces a compact, optimized mapping table instance for use by the runtime. The module also contains the data structures and algorithms used to simplify and compress the mapping ranges, such as merging adjacent ranges and encoding inline deltas. This module is explicitly noted as not being required for runtime IDN mappings, serving only as a build-time utility to generate the optimized table data.
okhttp-idna-mapping-table · high confidence
New duplex testing utilities for MockWebServer
Added AsyncRequestBody and MockSocketHandler classes to the okhttp-testing-support library to facilitate testing of HTTP/1.1 connection upgrades and duplex request/response scenarios. AsyncRequestBody allows test code to capture and reuse BufferedSinks for writing responses after the request body is consumed, while MockSocketHandler provides a scriptable interface for defining complex socket-level interactions, including receiving requests, sending responses, and handling stream cancellation or errors.
okhttp-testing-support/src/main/kotlin/okhttp3/internal/duplex · high confidence
New executeAsync extension for Kotlin coroutines
The library now exposes a public API for executing HTTP calls asynchronously using Kotlin coroutines. Specifically, the new \okhttp3.coroutines.ExecuteAsyncKt\ class provides an \executeAsync\ function that accepts an \okhttp3.Call\ and a \kotlin.coroutines.Continuation\, allowing developers to integrate OkHttp requests directly into coroutine-based workflows.
okhttp-coroutines/api · high confidence
New executeAsync extension for suspending HTTP calls
The okhttp-coroutines module now provides an executeAsync extension function that allows users to perform synchronous HTTP calls within a Kotlin coroutine context. This new API wraps the standard Call.enqueue mechanism, enabling developers to use suspend functions for network requests while ensuring proper cancellation and resource cleanup. The implementation includes a new module-info.java for Java Module System support and comprehensive tests covering timeouts, cancellations, and error handling.
okhttp-coroutines/src · high confidence
New guide samples for advanced HTTP and TLS scenarios
The guide now includes new recipe samples demonstrating how to intercept and validate TLS handshakes, customize cipher suites, stream request bodies using Okio pipes, perform preemptive basic authentication, track upload progress, and inspect detailed connection events via EventListener. Additional Kotlin examples show how to configure custom trust anchors, set up a local development server with insecure host acceptance, parse JSON responses with Moshi, upload files using the Okio Path API, and capture TLS keys for Wireshark debugging.
guide · high confidence
New in-memory fake network and TLS stack for testing
Added a complete in-memory socket system and TLS stack to the \okhttp-testing-support\ module, enabling tests to run without using any operating system TCP sockets. This includes \FakeNetwork\ for in-memory connection management, \FakeSocket\ and \FakeServerSocket\ to replace real network sockets, and \FakeTls\/\FakeSslSocket\ to simulate TLS handshakes and encryption. The suite also provides delegating wrappers (\DelegatingSSLSession\, \DelegatingSSLSocket\, \DelegatingSSLSocketFactory\, etc.) to facilitate socket configuration and interception, along with \FakeNetworkPlatform\ to integrate these fakes with OkHttp's existing platform abstraction.
okhttp-testing-support/src/main/kotlin/okhttp3/sockets · high confidence
New static file server sample with HTTPS support
Added a new SampleServer demo in the static-server sample that serves static files over HTTPS. The server accepts a keystore, password, root directory, and port via command-line arguments, configures an SSLContext, and uses MockWebServer to dispatch requests. It supports directory listings with HTML links and serves individual files with appropriate content types, returning 404 for missing files and 500 for server errors.
static-server · high confidence
New structured event recording and debugging utilities for tests
The testing support library now includes a comprehensive set of utilities to capture and inspect OkHttp's internal lifecycle events. Call and connection activities are represented by structured data classes in CallEvent and ConnectionEvent, which are populated by the new EventListenerAdapter. For test assertions, EventRecorder and RecordingConnectionListener allow you to capture these events, verify their sequence, and check timing. Additionally, debugging is enhanced with ClientRuleEventListener for logging, JsseDebugLogging for TLS handshake details, and EventListenerRelay to detect stale listener references.
okhttp-testing-support/src/main/kotlin/okhttp3 · high confidence
Support for third-party TLS providers on JVM
OkHttp now detects and uses BouncyCastle, Conscrypt, and OpenJSSE as the TLS platform when they are installed as the first security provider, enabling users to leverage these alternative cryptographic implementations for their HTTPS connections.
okhttp/src/jvmMain/kotlin/okhttp3/internal/platform · high confidence
Transparent Brotli response support via new interceptor
The library now includes a new \BrotliInterceptor\ that automatically adds the \Accept-Encoding: br\ header to outgoing requests and decompresses responses encoded with Brotli. This interceptor is implemented as a reusable \CompressionInterceptor\ that handles both Brotli and Gzip decoding, effectively replacing the previous transparent gzip handling in the core \BridgeInterceptor\ to provide broader compression support out of the box.
okhttp-brotli/src/main/kotlin · high confidence
API
Establishes public API surface for Server-Sent Events (SSE) module
The SSE module now exposes a defined public API contract via the \okhttp-sse.api\ file, explicitly declaring the public interfaces and classes for \EventSource\, \EventSource.Factory\, \EventSourceListener\, and the \EventSources\ utility class. This change formalizes the binary compatibility boundary for the SSE functionality, ensuring that public consumers interact only with the supported OkHttp public API components rather than internal implementation details.
okhttp-sse/api · high confidence
MockWebServer3 public API surface defined
This change introduces the public API contract for MockWebServer3, defining the core classes and interfaces used to mock HTTP interactions. It establishes the \MockWebServer\ class for starting/stopping the mock server and enqueuing responses, the \Dispatcher\ and \QueueDispatcher\ classes for handling incoming requests, and the \RecordedRequest\ class for inspecting captured requests, including new fields like \connectionIndex\ and decomposed request line properties. The API also defines \MockResponse\ and its \Builder\ for configuring response behavior (status, headers, body, delays, throttling, trailers, and socket effects), along with supporting types like \MockResponseBody\, \PushPromise\, and \SocketEffect\ for granular control over socket-level interactions.
mockwebserver/api · high confidence
OkHttp API surface split into Android and JVM variants
The public API definitions for OkHttp are now separated into platform-specific files (\okhttp/api/android/okhttp.api\ and \okhttp/api/jvm/okhttp.api\). This change reflects the modularization of the library, ensuring that the public contract exposed to Android applications and JVM applications is defined and versioned independently, allowing for platform-specific API evolution without breaking compatibility on the other platform.
okhttp/api · high confidence
Public API surface for HttpLoggingInterceptor and LoggingEventListener defined
The public API signature for the logging interceptor module is now explicitly defined, exposing the \HttpLoggingInterceptor\ class with its \Level\ enum (BASIC, BODY, HEADERS, NONE), \Logger\ interface, and methods for redacting headers and query parameters. Additionally, the \LoggingEventListener\ class and its \Factory\ are included in the public API, providing detailed lifecycle callbacks for HTTP calls such as DNS resolution, connection handling, and request/response body streaming. This change establishes the binary compatibility contract for these components, ensuring that existing user code relying on these classes and interfaces remains stable across library updates.
okhttp-logging-interceptor/api · high confidence
Architecture
Added binary compatibility API signatures for okhttp-tls and okhttp-urlconnection
New API signature files have been added for the okhttp-tls and okhttp-urlconnection modules to establish a baseline for binary compatibility validation. The okhttp-tls/api file documents the public interfaces for certificate handling classes, including Certificates, HandshakeCertificates (and its Builder), and HeldCertificate (and its Builder), ensuring that public methods and constructors remain stable across versions. Similarly, the okhttp-urlconnection/api file defines the public API for JavaNetAuthenticator and JavaNetCookieJar, locking in the expected signatures for these adapter classes to prevent accidental breaking changes in future releases.
okhttp-tls/api, okhttp-urlconnection/api · high confidence
Behavioural changes
Add JPMS-compatible API signature for JavaNetCookieJar
The okhttp-java-net-cookiejar module now includes an API signature file defining the public contract for the JavaNetCookieJar class. This change formalizes the class's visibility and method signatures (constructor, loadForRequest, saveFromResponse) to ensure compatibility with Java Platform Module System (JPMS) requirements, allowing the library to be properly used in modular Java applications.
okhttp-java-net-cookiejar/api · high confidence
Added ProGuard rules for OkHttp testing support
A new ProGuard configuration file (okhttp3.pro) has been added to the okhttp-testing-support module to suppress warnings related to optional classes used by the test platform. This ensures that builds using code shrinking and obfuscation tools like R8 or ProGuard complete without noise from missing optional dependencies in the testing support library.
okhttp-testing-support/src/main/resources · high confidence
DNS over HTTPS implementation now supports ECH service metadata and configurable address resolution
The DNS over HTTPS client now includes an \includeServiceMetadata\ option (defaulting to true) to request HTTPS DNS records required for Encrypted Client Hello (ECH), and exposes \resolvePrivateAddresses\ and \resolvePublicAddresses\ flags to control whether private or public IP addresses are returned during DNS lookups. A new internal \BootstrapDns\ class handles initial connection to the DNS server using hardcoded hosts or the system DNS, ensuring reliable resolution before the DoH connection is established.
okhttp-dnsoverhttps/src/main/kotlin/okhttp3/dnsoverhttps · high confidence
Decoupled Gradle build-logic convention plugins
The build system has been refactored to use a set of decoupled convention plugins in the \build-logic\ module, replacing the previous monolithic setup. This introduces dedicated plugins for JVM configuration (\okhttp.jvm-conventions\), OSGi bundle packaging via BND (\Osgi.kt\ and \BndBuildAction.kt\), Java module versioning (\JavaModules.kt\), and quality checks including Animal Sniffer and Spotless (\okhttp.quality-conventions\). The refactoring also adds Configuration Cache compatibility by extracting the BND build logic into a serializable \BndBuildAction\ class, enables Kotlin Multiplatform support for Java modules, and standardizes test execution and dependency management across all modules.
build-logic/src/main/kotlin · high confidence
Deprecate JavaNetAuthenticator and introduce JPMS-compatible JavaNetCookieJar
The JavaNetAuthenticator class is now deprecated in favor of using Authenticator.JAVA\_NET\_AUTHENTICATOR directly. Additionally, a new JavaNetCookieJar implementation is introduced that delegates to an internal class to ensure JPMS compatibility, with users advised to use the internal implementation directly for better package naming compliance.
okhttp-urlconnection/src/main/kotlin · high confidence
Deprecated API surface for mockwebserver
The \mockwebserver-deprecated/api\ module now publishes a binary compatibility API file (\mockwebserver.api\) that explicitly marks several \MockWebServer\ and \MockResponse\ methods as deprecated. Specifically, accessors and setters for \bodyLimit\, \port\, \protocolNegotiationEnabled\, \protocols\, \requestCount\, and \serverSocketFactory\ on \MockWebServer\, as well as header, HTTP/2 error code, socket policy, status, and trailer accessors on \MockResponse\, are flagged with \-deprecated\ annotations. This signals to users that these configuration and inspection methods are scheduled for removal or replacement in favor of newer APIs, likely aligning with the broader migration to \mockwebserver3\.
mockwebserver-deprecated/api · high confidence
Deprecated MockWebServer delegates to MockWebServer3
The \okhttp3.mockwebserver\ package has been replaced with a thin compatibility layer that forwards all operations to the new \mockwebserver3\ implementation. Users of the deprecated \MockWebServer\, \MockResponse\, \RecordedRequest\, and related classes will now interact with the underlying v3 engine, which introduces changes such as replacing \SocketPolicy\ with \SocketEffect\, exposing the request line as individual properties (method, path), and allowing the request body to be null or empty.
mockwebserver-deprecated/src/main/kotlin · high confidence
DnsOverHttps API stabilization and configuration updates
The public API for DnsOverHttps is now explicitly defined, exposing configuration options for IPv6 inclusion, service metadata, and address resolution scope (public vs private). The builder now supports setting a custom DnsCache for in-memory caching, allows specifying bootstrap DNS hosts, and lets users choose between a system DNS fallback or a custom one. The includeHttps parameter has been renamed to includeServiceMetadata to better reflect its purpose of including service metadata in responses.
okhttp-dnsoverhttps/api · high confidence
EventSource factory now automatically sets the Accept header
The EventSources.createFactory method in the Server-Sent Events (SSE) module now automatically adds the 'Accept: text/event-stream' header to outgoing requests if it is not already present. This ensures that SSE connections are correctly identified by the server without requiring manual header configuration by the user.
okhttp-sse/src/main/kotlin/okhttp3/sse · high confidence
Gradle daemon configured to use Java 21
The Gradle build now explicitly targets Java 21 (Adoptium) for the daemon process via a new gradle-daemon-jvm.properties file, ensuring consistent toolchain usage during builds.
gradle · high confidence
Introduce internal ASN.1 DER decoder and encoder
OkHttp now includes a built-in, internal ASN.1 DER decoder and encoder within the \okhttp3.tls.internal.der\ package. This new implementation replaces the previous reliance on Bouncy Castle for DER parsing and encoding, providing a lighter-weight, native Kotlin solution for handling X.509 certificate structures and other ASN.1 data. The change introduces a streaming reader and writer that strictly enforce DER constraints, such as rejecting indefinite length encodings and adhering to RFC 5280 time format rules, while also adding defensive checks against malformed input discovered during fuzzing.
okhttp-tls/src/main/kotlin/okhttp3/tls/internal/der · high confidence
JVM public suffix list uses resource-based loading
On the JVM platform, the public suffix list is now loaded via a resource-based implementation (ResourcePublicSuffixList) instead of the previous method. This change ensures that the list is correctly resolved from the classpath resources, which is the standard approach for JVM applications, improving compatibility and reliability for users running OkHttp on the JVM.
okhttp/src/jvmMain/kotlin/okhttp3/internal/publicsuffix · high confidence
OkHttp Android module now initializes automatically via AndroidX Startup
OkHttp on Android now registers an AndroidManifest.xml with an AndroidX Startup Initializer (PlatformInitializer) that automatically provides the application context to the platform layer. This enables features like cookie and URL domain handling without requiring manual initialization, though developers can still call OkHttp.initialize(Context) if they disable the initializer or run in environments like Robolectric.
okhttp/src/androidMain · high confidence
OkHttp core classes migrated to Kotlin
The core networking classes in the \okhttp3\ package—including \Address\, \Authenticator\, \Cache\, \CacheControl\, \Call\, \Callback\, \CertificatePinner\, \Challenge\, and \CipherSuite\—have been rewritten in Kotlin. This migration introduces immutable data classes with primary constructors, replaces Java-style getter methods with direct property accessors, and marks the legacy getter methods as deprecated with \DeprecationLevel.ERROR\ to enforce the new API style.
okhttp/src/commonJvmAndroid · high confidence
OkHttp module documentation and ProGuard configuration
The OkHttp module now includes a Module.md file describing the library as an HTTP+HTTP/2 client for Android and Java applications, and introduces a new okhttp3.pro file to configure ProGuard rules. This configuration suppresses warnings for JSR 305 annotations, Animal Sniffer dependencies, and internal platform classes related to Conscrypt and Bouncy Castle, ensuring smoother builds for Android and JVM environments using these security providers.
okhttp · high confidence
Refactored internal TLS trust management into dedicated Kotlin utilities
The internal TLS trust management logic in the okhttp-tls module has been restructured into new Kotlin files: TlsUtil, InsecureAndroidTrustManager, and InsecureExtendedTrustManager. TlsUtil now provides static factory methods (newTrustManager, newKeyManager) to create trust and key managers, automatically selecting the appropriate insecure host handling strategy based on the platform (Android vs. others). InsecureAndroidTrustManager handles certificate verification bypass for specific hosts on Android using reflection to access platform-specific methods, while InsecureExtendedTrustManager performs the same function on non-Android platforms by extending X509ExtendedTrustManager. This change centralizes the internal implementation details for insecure host handling and trust manager creation within the internal package.
okhttp-tls/src/main/kotlin/okhttp3/tls/internal · high confidence
Server-Sent Events implementation moved to new internal package
The internal implementation of Server-Sent Events has been relocated from \okhttp3.internal.sse\ to \okhttp3.sse.internal\. This change involves the introduction of \RealEventSource.kt\ and \ServerSentEventReader.kt\ in the new package, replacing the previous internal structure. Users relying on internal APIs should note this package rename, although the public \EventSource\ API remains unchanged.
okhttp-sse/src/main/kotlin/okhttp3/sse/internal · high confidence
Stabilize the JUnit 4 API with binary compatibility validation
The JUnit 4 integration now exposes a stable public API for the MockWebServerRule class, which extends JUnit's ExternalResource and provides access to the underlying MockWebServer instance. This stabilization is enforced by adopting Kotlin's binary compatibility validator, ensuring that future changes to this public interface are detected and managed to prevent breaking changes for existing users.
mockwebserver-junit4/api · high confidence
Version property template for okcurl
A new version property template file (okcurl-version.properties) has been added to the resources-templates directory, containing a placeholder for the project version. This allows the build system to inject the actual version number into the properties file during the build process, ensuring the okcurl tool reports the correct version.
okcurl/src/main/resources-templates · high confidence
Test coverage
Add regression-test module for Android compatibility verification; Added Android DNS tests with Robolectric shadows for API 37; Added Android instrumentation test for Let's Encrypt ISRG Root X1 certificate; Added Android tests and configuration for Encrypted Client Hello (ECH); Added Android-specific unit tests for OkHttp initialization and logging; Added HPACK interop and round-trip tests in Kotlin; Added HPACK test case submodule; Added HTTP/2 server test utility; Added JUnit 5 tests for BrotliInterceptor; Added JVM WebSocket tests for compression, framing, and connection lifecycle; Added JVM platform tests for JDK 8, JDK 9, and base Platform; Added JVM tests for concurrent task scheduling and IDNA encoding; Added JVM tests for connection pool, route selection, and ECH retry logic; Added JVM-specific TLS tests for certificate pinning, client auth, and hostname verification; Added Kotlin source-compatibility and functional tests for MockWebServer; Added Kotlin test for MockWebServerRule lifecycle; Added Kotlin-based unit tests for HttpLoggingInterceptor and LoggingEventListener; Added OSGi integration and JavaNetAuthenticator tests; Added TLS certificate and handshake tests in Java and Kotlin; Added baseline HTTP client comparison tests; Added comprehensive JVM tests for DiskLruCache using Burst; Added comprehensive tests for DNS-over-HTTPS functionality; Added internal HTTP and parsing tests for Server-Sent Events; Added internal test utilities and unit tests for DNS, hostnames, tags, and socket health; Added native-image tests for PublicSuffixDatabase and basic connectivity; Added test for ALPN override on Android; Added test resources for IDN and URL parsing; Added test to verify sample guide main classes; Added tests for Call tag seeding and computation; Added tests for CompressionInterceptor, Dns values, and versioning; Added tests for FakeNetwork and FakeTls testing utilities; Added tests for Java module visibility and integration; Added tests for MockWebServer3 core functionality; Added tests for OkHttpClientTestRule exception handling; Added tests for PlatformRule validation; Added tests for SNI override behavior on Android; Added tests for UTF-8 detection logic; Added tests for the Public Suffix Database; Added tests for the internal ASN.1 DER decoder and certificate parsing; Added tests for the new DNS resolution state machine and caching; Expanded Android instrumentation test coverage; HTTP/2 test suite migrated to JUnit 5 and Kotlin; JVM-specific public suffix test infrastructure added; Migrated JVM tests to JUnit 5 and added comprehensive test coverage; Migrated okcurl tests to Kotlin; New and updated tests for HTTP connection handling and upgrades; New testing support utilities for platform-aware and flaky tests; Updated Robolectric test SDK to version 36.
Dependencies
Migrate to a modern Gradle build with Version Catalogs and AGP 9
The build system has been completely overhauled to use Gradle Kotlin DSL, Version Catalogs (libs.versions.toml), and decoupled convention plugins in build-logic. This upgrade targets Android Gradle Plugin 9.1.1 and Kotlin 2.2.21, enabling features like the new AGP DSL and configuration cache. The migration also updates core dependencies such as Okio to 3.18.2, JUnit 5 to 1.14.4, and Spotless to 8.10.2, while introducing new modules like android-test and android-test-app to centralize and modernize Android-specific testing.
(dependencies) · high confidence
Upgrade Gradle wrapper to version 9.6.1
The Gradle wrapper configuration has been updated to use Gradle 9.6.1. This change ensures that builds will automatically download and use this specific version of the Gradle build tool, providing consistency across development environments and leveraging the features and bug fixes included in this release.
gradle/wrapper · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 35 → 54 (+18.3)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 93 → 87 (-5.7)
- Architecture 96 → 98 (+2.1)
- Maturity 50 → 59 (+9.2)
- Readiness 28 → 38 (+10.4)
- Security 20 → 63 (+42.8)
Resolved (116)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- Duplicated block (18 lines × 2) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/connection/ConnectPlan.kt)
- Duplicated block (55 lines × 2) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/http2/Hpack.kt)
- Duplicated block (73 lines × 2) (okhttp-logging-interceptor/src/main/kotlin/okhttp3/logging/LoggingEventListener.kt)
- Duplicated block (73 lines × 3) (okhttp-testing-support/src/main/kotlin/okhttp3/ClientRuleEventListener.kt)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- …and 96 more
New (208)
- -CacheControlCommonKt.commonParse (cognitive 22) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/-CacheControlCommon.kt)
- -CacheControlCommonKt.commonParse (cyclomatic 23) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/-CacheControlCommon.kt)
- -CacheControlCommonKt.commonToString (cognitive 27) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/-CacheControlCommon.kt)
- -HostnamesCommonKt.decodeIpv4Suffix (cognitive 23) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/-HostnamesCommon.kt)
- -HostnamesCommonKt.decodeIpv6 (cognitive 35) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/-HostnamesCommon.kt)
- -HostnamesCommonKt.decodeIpv6 (cyclomatic 17) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/-HostnamesCommon.kt)
- -HostnamesCommonKt.inet6AddressToAscii (cognitive 16) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/-HostnamesCommon.kt)
- -UrlKt.writeCanonicalized (cognitive 39) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/url/-Url.kt)
- -UrlKt.writeCanonicalized (cyclomatic 20) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/url/-Url.kt)
- AlpnProvider.invoke (cognitive 23) (okhttp/src/jvmMain/kotlin/okhttp3/internal/platform/Jdk8WithJettyBootPlatform.kt)
- BasicCertificateChainCleaner.clean (cognitive 17) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/tls/BasicCertificateChainCleaner.kt)
- BndBuildAction.execute (cognitive 20) (build-logic/src/main/kotlin/BndBuildAction.kt)
- BndBuildAction.execute (cyclomatic 17) (build-logic/src/main/kotlin/BndBuildAction.kt)
- Builder.parse (cognitive 43) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/HttpUrl.kt)
- Builder.parse (cyclomatic 26) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/HttpUrl.kt)
- CacheInterceptor.intercept (cognitive 24) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/cache/CacheInterceptor.kt)
- CacheInterceptor.intercept (cyclomatic 18) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/cache/CacheInterceptor.kt)
- CacheQuery.enqueue (cognitive 20) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/dns/RealDnsCache.kt)
- CallServerInterceptor.intercept (cognitive 40) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/http/CallServerInterceptor.kt)
- CallServerInterceptor.intercept (cyclomatic 29) (okhttp/src/commonJvmAndroid/kotlin/okhttp3/internal/http/CallServerInterceptor.kt)
- …and 188 more
Changes since last survey
- 82 commits — 78 feature/other, 4 fixes
By area
- gradle/libs.versions.toml — 23 commits
- .github/workflows — 18 commits
- okhttp/src — 14 commits
- (root) — 6 commits
- okhttp-dnsoverhttps/src — 3 commits
- okhttp-testing-support/src — 3 commits
- build-logic/build.gradle.kts — 2 commits
- build-logic/src — 2 commits
- .github/renovate.json — 1 commit
- android-test/build.gradle.kts — 1 commit
- android-test/src — 1 commit
- container-tests/build.gradle.kts — 1 commit
- container-tests/src — 1 commit
- docs/contribute — 1 commit
- docs/security — 1 commit
- maven-tests/.mvn — 1 commit
- mockwebserver-junit5/src — 1 commit
- okhttp/build.gradle.kts — 1 commit
- samples/android — 1 commit
Notable commits
- fix: Remove BUG-BOUNTY.md (#9751)
- fix: Revert "Use a fixed size for DoH request body" (#9686)
- fix: Use a fixed size for DoH request body
- fix: Use a fixed size for DoH request body (#9687)
- change: Fold EchAwareDns into AndroidDns (#9645)
- change: Add .java-version for the publish workflow (#9649)
- change: Add an ECH sample (#9617)
- change: Add overdue tests for FakeNetwork (#9638)
- change: Another tpyo
- change: Change DnsOverHttps to query the correct port per Attrleaf (#9650)
- change: Completely fake out TLS for testing (#9640)
- change: Completely fake out the network for simple tests (#9636)
- change: Copy website contributing content into repo one (#9676)
- change: Deduplicate Spotless version (#9703)
- change: Delete container tests (#9736)
- change: Disable Loom CI shard (#9668)
- change: Don't close the multipart sink when a part closes its stream (#9659)
- change: Don't recover after an ECH public_name fails to verify (#9680)
- change: End-to-end test for securely disabling ECH (#9662)
- change: Fix some changelog typos
- …and 62 more
Architecture
- Containers 0 added · 0 removed · contexts 12 added · 0 removed · edges 10 added · 0 removed
Added bounded contexts (12)
- guide
- mockwebserver
- mockwebserver-junit4
- okhttp
- okhttp-brotli
- okhttp-idna-mapping-table
- okhttp-testing-support
- okhttp-tls
- okhttp-zstd
- static-server
- tlssurvey
- unixdomainsockets
Added dependency edges (10)
- guide → okhttp
- guide → okhttp-tls
- mockwebserver → okhttp
- mockwebserver-junit4 → mockwebserver
- okhttp-brotli → okhttp
- okhttp-testing-support → mockwebserver
- okhttp-testing-support → okhttp (coupling)
- okhttp-testing-support → okhttp-tls
- okhttp-zstd → okhttp
- tlssurvey → okhttp
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
lysine-dev/okhttp was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 40a3b8749deaacf60a04c890aed052cb14ad36ee — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.