square/okhttp
46.0
Weak · 5 August 2026
53.8k
lines of production code
Kotlin
with Java
4
measurements over time
What this system is
This system is a modern, modular HTTP client library for Java and Android that provides a comprehensive suite of networking capabilities. It supports advanced features such as HTTP/2, Server-Sent Events, and DNS over HTTPS, while offering robust testing utilities and a mock server for development. The architecture is split into platform-specific and common modules, with full support for Java 9+ modules, GraalVM native images, and Kotlin coroutines.
How it got here
2012–2020 — Kotlin migration and testing expansion
45 changes.
This period was defined by the comprehensive migration of the OkHttp codebase to Kotlin, including the implementation of new features like Brotli support, Server-Sent Events, and DNS over HTTPS. The team significantly expanded test coverage by modernizing the test suite to JUnit 5 and Kotlin, while also introducing extensive sample applications and documentation to guide developers.
2021–2023 — API stabilization and test expansion
29 changes.
This period focused on formalizing public APIs across multiple OkHttp modules, including SSE, TLS, and DNS over HTTPS, while introducing new features like GraalVM native image support and Brotli compression. Significant effort was also directed toward expanding test coverage, particularly for Android, HTTP/2, and logging components, alongside migrating test suites to Kotlin.
2024–2026 — Multi-platform architecture and test modernization
23 changes.
This period focused on restructuring OkHttp's codebase to support distinct Android and JVM targets, introducing Kotlin coroutine integration, and modernizing the test suite with JUnit 5 and containerized integration tests. The work also included adding Java 9+ module support and refactoring the Gradle build system for improved reliability and cacheability.
Features
Add Android regression test module for cross-client HTTP/2 and certificate validation
A new \regression-test\ module has been added to run Android instrumentation tests against an emulator or device. This module includes tests for OkHttp, the Android \HttpEngine\, and the Apache HTTP Client 5.x to verify HTTP/2 and certificate validation behavior across different clients. Specific test cases cover general HTTP/2 connectivity, Let's Encrypt root certificate handling on older Android versions, and baseline HTTP/1.1 vs HTTP/2 negotiation.
regression-test · high confidence
Add Brotli compression support to OkHttp
The library now includes a public API for Brotli compression, exposing the \okhttp3.brotli.Brotli\ class to handle decompression and the \okhttp3.brotli.BrotliInterceptor\ for integration. This allows users to enable Brotli encoding/decoding alongside existing compression algorithms.
okhttp-brotli/api, okhttp-zstd/api · high confidence
Add Crawler sample application
A new Crawler sample has been added to the codebase. This Java application demonstrates how to build a multi-threaded web crawler using OkHttp and Jsoup. It fetches HTML pages, follows links, and respects host limits and cache settings, providing a practical example of concurrent request handling and resource management.
samples/crawler · high confidence
Add GraalVM native-image configuration for OkHttp
New configuration files have been added to support building OkHttp as a GraalVM native image. This includes a native-image.properties file to enable HTTP/HTTPS protocols and register a custom feature, a reflect-config.json to expose necessary Kotlin classes for reflection, and a resource-config.json to include the PublicSuffixDatabase. These changes enable users to compile OkHttp into a native binary for improved startup time and reduced memory footprint in GraalVM environments.
okhttp/src/jvmMain/resources · high confidence
Add JUnit 5 @StartStop extension for lifecycle management
A new @StartStop annotation is introduced in the mockwebserver3-junit5 module, enabling JUnit 5 users to manage the MockWebServer lifecycle automatically during tests.
mockwebserver-junit5/api · high confidence
Add Java 9+ module descriptor for OkHttp
A new module-info.java file has been added to the OkHttp JVM implementation, enabling support for Java 9+ modules. This change allows OkHttp to be used as a proper Java module, exposing internal packages such as concurrent, connection, http, http2, platform, publicsuffix, and ws to specific dependent modules like mockwebserver and logging, while requiring kotlin.stdlib, okio, and java.logging.
okhttp/src/jvmMain/java9 · high confidence
Add Java 9+ module support and migrate test to Kotlin
The mockwebserver-junit4 module now includes a Java 9+ module descriptor (module-info.java) that declares the 'mockwebserver3.junit4' module, requiring 'okhttp3' and 'java.logging', and exports the 'mockwebserver3.junit4' package. Additionally, the test suite for this module has been converted from Java to Kotlin, as shown by the new MockWebServerRuleTest.kt file which exercises the MockWebServerRule behavior using JUnit 4 and assertk assertions.
mockwebserver-junit4/src · high confidence
Add JavaNetCookieJar to bridge Java's CookieHandler with OkHttp
A new public API, JavaNetCookieJar, has been added to the okhttp-java-net-cookiejar module. This class implements OkHttp's CookieJar interface by delegating to a java.net.CookieHandler, enabling seamless integration with the Java standard library's cookie management. The implementation handles saving cookies from HTTP responses and loading cookies for requests, including parsing and normalizing cookie headers to prevent crashes on malformed values.
okhttp-java-net-cookiejar/src/main/kotlin · high confidence
Add Kotlin recipe samples for OkHttp guide
The OkHttp guide now includes a comprehensive set of Kotlin recipe samples, providing idiomatic Kotlin implementations for common HTTP tasks. New examples cover synchronous and asynchronous requests, header access, authentication, caching, call cancellation, certificate pinning, timeout configuration, per-call settings, and various POST methods (file, form, multipart, streaming, and string uploads). Additionally, specialized recipes demonstrate upload progress tracking and client authentication using a Yubikey hardware key.
samples/guide/src/main/java/okhttp3/recipes/kt · high confidence
Add Maven wrapper and example recipes for testing and debugging
The maven-tests module now includes a Maven wrapper (mvnw) configured to use Maven 4.0.0-rc-5 and Maven Wrapper 3.3.4, enabling consistent builds. Additionally, new example recipes were added to the guide samples: a basic HTTP client test, a handshake checker that rejects specific certificates, a custom cipher suite configuration, a streaming post using Okio pipes, a preemptive basic auth interceptor, an event logger for debugging, an upload progress tracker, and a static file server. These serve as practical examples for common OkHttp patterns.
maven-tests · high confidence
Add OkCurl tool and documentation
Introduced the OkCurl utility, an OkHttp-backed curl clone for testing OkHttp's HTTP engine against web servers. This includes a new README.md file explaining the tool's purpose and usage, as well as an executable shell script (okcurl) that builds and runs the tool using Gradle and GraalVM.
okcurl · high confidence
Add OkHttp contributors sample using Moshi
A new sample application, OkHttpContributors.java, has been added to the simple-client directory. This example demonstrates fetching and parsing GitHub repository contributors from the API, utilizing Moshi for JSON deserialization and the try-with-resources pattern for proper response handling.
samples/simple-client · high confidence
Add Slack sample app demonstrating OAuth and WebSocket integration
A new sample application in the samples/slack directory demonstrates integrating with the Slack API using OkHttp. The sample includes an OAuth flow to obtain user authorization and establishes a real-time messaging session using WebSockets. It provides a complete example of handling OAuth sessions, exchanging authorization codes, and managing WebSocket connections for real-time communication.
samples/slack · high confidence
Add TLS survey sample to test cipher suite support across clients
A new 'tlssurvey' sample was added to the repository, providing a tool to survey TLS cipher suite support across various clients. The implementation includes a Kotlin-based client configuration system (Clients.kt) that defines cipher suites for modern and historic versions of OkHttp (3.9, 3.11, 3.13, 3.14, 4.10), the current JVM, and Conscrypt. It also integrates with the SSL Labs API (SslLabsClient.kt, SslLabsApi.kt) to fetch real-world client data from the internet. The survey runner (RunSurvey.kt) aggregates this data to analyze and compare the TLS capabilities of different browsers, operating systems, and libraries.
samples/tlssurvey · high confidence
Add UNIX domain socket sample supporting HTTP/2
A new sample application demonstrates how to use UNIX domain sockets with OkHttp and MockWebServer. The example configures both the client and server to use HTTP/2 (specifically H2\_PRIOR\_Knowledge), allowing users to see how to establish connections over UNIX sockets for local inter-process communication.
samples/unixdomainsockets · high confidence
Add example code for GET and POST requests
New sample files, GetExample.java and PostExample.java, have been added to the okhttp3.guide package. These provide concrete examples of how to perform HTTP GET and POST requests using the OkHttpClient, including handling response bodies and constructing request bodies with media types.
samples/guide/src/main/java/okhttp3/guide · high confidence
Add new recipe samples for OkHttp 3
The samples/guide/src/main/java/okhttp3/recipes directory now includes a comprehensive set of new example files (such as AccessHeaders, AsynchronousGet, CacheResponse, CertificatePinning, and Progress) that demonstrate how to use the OkHttp 3 API. These samples cover common use cases including configuring timeouts, handling authentication, managing caches, and tracking progress, providing updated guidance for developers migrating to or using the latest OkHttp version.
samples/guide/src/main/java/okhttp3/recipes · high confidence
Add okcurl-version.properties template for version injection
A new template file, okcurl-version.properties, is added to the resources-templates directory. This file contains a placeholder for the project version, allowing the build system to inject the current version number into the properties file during the build process.
okcurl/src/main/resources-templates · high confidence
Added Android test app with multi-process and IDNA support
The android-test-app module was introduced, providing a test application that supports multi-process execution (via a secondary activity in a separate process) and includes specific ProGuard keep rules for IDNA mapping. The app also features tests for IDNA hostname handling and public suffix database validation, alongside a network security configuration that disables cleartext traffic.
android-test-app · high confidence
Added Java 9+ module descriptors for OkHttp submodules
New module-info.java files have been added to the root, mockwebserver, okhttp-brotli, okhttp-dnsoverhttps, okhttp-java-net-cookiejar, okhttp-logging-interceptor, okhttp-sse, okhttp-tls, and okhttp-urlconnection modules. These changes enable the library to be used as a Java Platform Module System (JPMS) module, allowing developers to declare explicit dependencies and exports for these specific OkHttp components when building multi-release JARs or using the Java 9+ module system.
(repo-wide) · high confidence
Added JavaNetAuthenticator and JavaNetCookieJar classes
New Kotlin classes, JavaNetAuthenticator and JavaNetCookieJar, were added to the okhttp3 package. JavaNetAuthenticator is marked as deprecated in favor of using Authenticator.Companion.JAVA\_NET\_AUTHENTICATOR, while JavaNetCookieJar delegates to an internal implementation to support JPMS compatibility.
okhttp-urlconnection/src/main/kotlin · medium confidence
Added LoggingFilesystem for testing
A new LoggingFilesystem class has been added to the okhttp-testing-support module. This class extends ForwardingFileSystem to log filesystem operations such as appending sinks, atomic moves, creating directories, deleting files, and reading/writing sources, which can be used in tests to observe or verify filesystem interactions.
okhttp-testing-support/src/main/kotlin/okhttp3/okio · medium confidence
Exposed coroutines extension for executing HTTP calls asynchronously
The public API for the \okhttp3.coroutines\ package now includes the \ExecuteAsyncKt\ class, which provides an \executeAsync\ function. This function allows users to execute an \okhttp3.Call\ using Kotlin coroutines, enabling asynchronous HTTP requests to be handled within a coroutine context.
okhttp-coroutines/api · high confidence
Implemented custom DNS message reader and writer for DNS over HTTPS
Added new internal classes DnsMessageReader and DnsMessageWriter to handle the encoding and decoding of DNS messages over HTTPS. The reader parses DNS responses including A, AAAA, and HTTPS records, while the writer constructs DNS queries and serializes resource records. This replaces the previous approach with a dedicated, self-contained implementation for parsing and generating DNS wire format data.
okhttp-dnsoverhttps/src/main/kotlin · high confidence
Initial repository structure and documentation site setup
The repository was initialized with essential configuration files including .editorconfig, .gitattributes, and .gitignore to standardize formatting and build artifacts. A comprehensive CHANGELOG.md was added to track version history, and a MkDocs-based documentation site was configured (mkdocs.yml) to host the project's guides, recipes, and API references. Additionally, the project includes a BUG-BOUNTY.md file outlining the security reporting process, alongside standard license and contributing guidelines.
(repo-wide) · high confidence
Introduce compact IDNA mapping table generation tooling
Added a new \okhttp-idna-mapping-table\ module that provides tools for building and generating a compact IDNA mapping table. This includes a Kotlin script (\GenerateIdnaMappingTableCode.kt\) to parse the Unicode IDNA mapping data and generate optimized Kotlin source code, alongside supporting classes (\IdnaMappingTableData\, \MappingTables.kt\) that handle the compact encoding of sections, ranges, and mappings. The module also includes tests for the table simplification and encoding logic.
okhttp-idna-mapping-table · high confidence
Introduce internal ASN.1 DER encoder/decoder for certificate parsing
Added a new internal \okhttp3.tls.internal.der\ package containing a streaming ASN.1 DER encoder and decoder (\DerReader\, \DerWriter\, \DerAdapter\) and adapters for certificate fields like validity times and algorithm identifiers. This replaces the previous reliance on Bouncy Castle for PKCS8 to PKCS1 conversion and enables round-trip certificate encoding/decoding. The implementation enforces DER rules, such as rejecting indefinite length encodings and honoring RFC 5280 requirements for time formats.
okhttp-tls/src/main/kotlin/okhttp3/tls/internal/der · high confidence
Introduce the okcurl command-line tool
Added the okcurl command-line interface, providing a curl-like experience for making HTTP requests. The new Main class parses command-line arguments for request methods, headers, timeouts, and SSL options, while internal modules handle request creation, response streaming, and debug logging.
okcurl/src/main/kotlin · high confidence
Introduces new testing and internal support classes for OkHttp
Adds several new classes to the testing and internal support libraries to improve testability and debugging. The \okhttp-testing-support\ module receives \CallEvent\, \ConnectionEvent\, \EventRecorder\, \RecordingConnectionListener\, \FakeProxySelector\, \JsseDebugLogging\, and \SpecificHostSocketFactory\ to facilitate testing and debugging of call and connection lifecycle events. Additionally, \TaskFaker\ is added to the \okhttp3.internal.concurrent\ package to provide a deterministic, sequential execution environment for \TaskRunner\ tests. The \mockwebserver3\ module introduces \MockWebServerRule\ for JUnit 4 integration, along with internal classes like \MockResponse\, \BufferMockResponseBody\, and \MockWebServerSocket\ to support the new builder-based API. Finally, new internal classes are added for DNS-over-HTTPS (\DnsMessage\), IDNA mapping (\MappedRange\, \SimpleIdnaMappingTable\), and Brotli compression (\Brotli\), enhancing the library's capabilities in these areas.
unixdomainsockets · high confidence
MockWebServer3 public API stabilization
The public API for MockWebServer3 is now explicitly defined and stabilized. This includes a new Builder pattern for constructing MockResponse objects, the introduction of a dedicated MockResponseBody class, and the addition of socket-level control via the SocketEffect interface. Additionally, RecordedRequest now exposes a connectionIndex and individual request line properties, while the Dispatcher interface and QueueDispatcher implementation are formally exposed.
mockwebserver/api · high confidence
Native image support for OkHttp
OkHttp now includes configuration for native image builds, allowing the library to be used in GraalVM-based applications. A new native-image.properties file defines the necessary arguments and features to ensure proper functionality in a native image environment.
okhttp/src/main · high confidence
New @StartStop annotation for automatic MockWebServer lifecycle management in JUnit 5 tests
A new \@StartStop\ annotation and corresponding JUnit 5 extension have been added to the \mockwebserver-junit5\ module. This feature allows developers to annotate \MockWebServer\ fields, automatically starting the server before each test and closing it afterward, simplifying test setup and teardown. The implementation includes the \StartStop\ annotation, the \StartStopExtension\ that handles the lifecycle, and a \module-info.java\ for Java 9+ module support. Tests confirm that annotated servers start and close correctly, while non-annotated ones do not.
mockwebserver-junit5/src · high confidence
New Kotlin-based TLS certificate and handshake utilities
The TLS module now includes new Kotlin source files (Certificates.kt, HandshakeCertificates.kt, HeldCertificate.kt) that provide utilities for decoding and encoding X.509 certificates in PEM format, managing handshake certificates and trust managers, and generating self-signed certificates. The HandshakeCertificates.Builder adds an addInsecureHost() method to allow unauthenticated connections to specific hosts for testing, and the build process now fails if private keys cannot be encoded. These changes consolidate certificate handling logic into the Kotlin source directory.
okhttp-tls/src/main/kotlin/okhttp3/tls · high confidence
New coroutine-based HTTP call execution in okhttp3.coroutines
The library now provides a Kotlin coroutine-friendly way to execute HTTP calls asynchronously via the new \okhttp3.coroutines\ package. This includes a \module-info.java\ for Java 9+ module support and an \ExecuteAsync.kt\ implementation that wraps OkHttp's \Call\ with \suspendCancellableCoroutine\ to allow suspending HTTP requests. A corresponding test suite \ExecuteAsyncTest.kt\ validates the new functionality, including timeout and cancellation handling.
okhttp-coroutines/src · high confidence
New testing utilities and event recording infrastructure
The testing support library received a suite of new helper classes to improve test reliability and debugging. A new \ClientRuleEventListener\ and \EventListenerAdapter\ provide structured, timestamped logging of all HTTP call events, while \EventListenerRelay\ helps detect stale listener caching bugs. Additional test utilities include \FailingCall\ for simulating failed calls, \FakeDns\ for mocking DNS resolution, and delegation wrappers for SSL sessions, sockets, and socket factories. The \OkHttpClientTestRule\ was updated to integrate these new event listeners and support Loom-based task runners, providing more deterministic and observable test environments.
okhttp-testing-support/src/main/kotlin/okhttp3 · high confidence
New testing utilities for duplex HTTP connections
Added AsyncRequestBody and MockSocketHandler classes to the testing support library to facilitate testing of duplex HTTP/1.1 connection upgrades. AsyncRequestBody provides a queue of BufferedSinks for capturing request bodies during duplex interactions, while MockSocketHandler offers a scriptable way to define expected request/response flows and socket behaviors for testing purposes.
okhttp-testing-support/src/main/kotlin/okhttp3/internal/duplex · high confidence
Public API for DNS over HTTPS exposed
The public API for DNS over HTTPS is now explicitly defined, exposing the DnsOverHttps class and its Builder for configuring DNS resolution over HTTPS, including options for IPv6, private/public address resolution, and custom clients.
okhttp-dnsoverhttps/api · high confidence
Public API for Server-Sent Events (SSE) in Kotlin
The OkHttp SSE module now exposes a public Kotlin API for working with Server-Sent Events. This includes the \EventSource\ interface and its \Factory\ for creating event source instances, the \EventSourceListener\ abstract class for handling SSE lifecycle events (open, event, close, failure), and the \EventSources\ utility object which provides a \createFactory\ method to instantiate the default SSE implementation. These components are located in the \okhttp3.sse\ package, making the SSE functionality accessible to Kotlin users without relying on internal or Java-specific entry points.
okhttp-sse/src/main/kotlin/okhttp3/sse · high confidence
API
New public API for HttpLoggingInterceptor and LoggingEventListener
The public API surface for the OkHttp logging interceptor has been formalized, exposing the HttpLoggingInterceptor class with its Level enum and Logger interface, alongside a new LoggingEventListener class and its associated Factory. This change provides a stable, documented contract for developers integrating or extending the logging functionality, ensuring binary compatibility for future updates.
okhttp-logging-interceptor/api · high confidence
Architecture
OkHttp API surface split into Android and JVM variants
The public API definitions for OkHttp are now separated into platform-specific modules: \okhttp/api/android/okhttp.api\ and \okhttp/api/jvm/okhttp.api\. This change reflects the architectural split of the library into Android and JVM targets, ensuring that each platform exposes only the classes and methods relevant to that environment while maintaining a consistent core API.
okhttp/api · high confidence
OkHttp core refactored into common and platform-specific modules
The OkHttp library has been restructured by splitting the core into separate modules for the common code and the Android/JVM implementations. This change moves core classes like \Address\, \Authenticator\, \Call\, \Callback\, \CacheControl\, \Challenge\, \CipherSuite\, \Connection\, \ConnectionPool\, and \ConnectionSpec\ into the \okhttp/src/commonJvmAndroid\ directory, indicating a move towards a shared codebase for Android and JVM platforms. Users will see these classes and their associated APIs consolidated in the common module, potentially affecting how the library is imported and configured in multi-platform projects.
okhttp/src/commonJvmAndroid · high confidence
Behavioural changes
Add JPMS-compatible API for JavaNetCookieJar
The public API for the JavaNetCookieJar class is now exposed in the module-info, making the component compatible with Java Platform Module System (JPMS) requirements. This change ensures that the cookie jar functionality is properly exported and accessible to other modules in a modular Java environment.
okhttp-java-net-cookiejar/api · high confidence
Added module documentation and ProGuard rules for OkHttp
The OkHttp artifact now includes a Module.md file providing a description of the HTTP client for Android and Java applications, alongside a new okhttp3.pro file containing ProGuard rules. These rules configure the build to ignore warnings related to JSR 305 annotations, Animal Sniffer dependencies, and internal platform classes used for security providers like Conscrypt and Bouncy Castle.
okhttp · medium confidence
Adds JVM-specific OkHttp initialization and version access
A new JVM-specific implementation of the OkHttp object is introduced in the jvmMain source set, exposing the library's version string via a public field. This change provides a platform-specific entry point for JVM-based applications to access OkHttp's version information, aligning with the commit's intent to support Android/JVM initialization patterns.
okhttp/src/jvmMain/kotlin/okhttp3 · medium confidence
Android platform support restructured with new platform initialization and logging
OkHttp for Android now uses a new \ContextAwarePlatform\ and \PlatformInitializer\ to manage the application context and platform selection, replacing the previous static initialization approach. The \PlatformRegistry\ now explicitly handles Android API level checks and falls back to JVM/Robolectric behavior when needed. Additionally, a new \AndroidLog\ system routes Java \java.util.logging\ output to Android's \Log\ system, improving debuggability and handling edge cases like Paparazzi or non-Robolectric tests. The \PublicSuffixList\ is now backed by Android assets via \AssetPublicSuffixList\. These changes collectively modernize how OkHttp initializes and logs on Android, ensuring better compatibility with modern Android development practices and testing frameworks.
okhttp/src/androidMain/kotlin · high confidence
Centralized build configuration properties in OkHttpBuildUtils
A new Kotlin file, OkHttpBuildUtils.kt, has been added to the build-logic module to centralize access to Gradle project properties. This change introduces extension properties for retrieving the target platform (defaulting to jdk9), the Java version for tests (defaulting to 21), whether an Android build is being performed, and the ALPN boot version. This refactoring supports the adoption of a modern Gradle build by providing a single source of truth for these build-time configurations.
build-logic/src/main/kotlin/okhttp3 · high confidence
Deprecated MockWebServer API bridges to new mockwebserver3 implementation
The \mockwebserver-deprecated\ module now provides a compatibility layer that maps the legacy \okhttp3.mockwebserver\ API to the new \mockwebserver3\ implementation. This includes new classes like \DeprecationBridge\, \Dispatcher\, \MockResponse\, \MockWebServer\, \PushPromise\, \QueueDispatcher\, \RecordedRequest\, and \SocketPolicy\ that wrap the new types. Users interacting with the deprecated package will find that their existing code continues to function, but the underlying implementation has shifted to the new API, ensuring a smooth transition without immediate breaking changes.
mockwebserver-deprecated/src/main/kotlin · high confidence
Gradle daemon JVM configured for Java 21
A new configuration file, gradle/gradle-daemon-jvm.properties, has been added to specify that the Gradle daemon should run on the Adoptium JDK 21 toolchain. This ensures the build process uses a modern Java version for improved performance and compatibility.
gradle · high confidence
Internal TLS utilities and trust managers moved to Kotlin
The internal TLS utilities and trust manager implementations have been migrated from Java to Kotlin. This includes the new files InsecureAndroidTrustManager.kt, InsecureExtendedTrustManager.kt, and TlsUtil.kt in the okhttp3.tls.internal package. The TlsUtil object now provides factory methods for creating trust and key managers, selecting the appropriate trust manager implementation (Android-specific or extended) based on the platform.
okhttp-tls/src/main/kotlin/okhttp3/tls/internal · medium confidence
Introduce BrotliInterceptor for transparent Brotli support
A new BrotliInterceptor object has been added to the library, implementing the shared CompressionInterceptor interface to provide transparent Brotli response handling. This replaces the previous transparent gzip compression previously handled by BridgeInterceptor, allowing the client to automatically negotiate and decode Brotli-encoded responses.
okhttp-brotli/src/main/kotlin · high confidence
Introduce binary compatibility API for SSE components
A new public API file (okhttp-sse.api) is added to the project, formally declaring the binary compatibility surface for Server-Sent Events (SSE) classes. This includes the EventSource interface, the EventSource.Factory interface, the EventSourceListener abstract class, and the EventSources utility class. This change ensures that the public contract for these components is explicitly maintained and validated by the binary compatibility validator.
okhttp-sse/api · medium confidence
JVM platform selection and native image support
OkHttp on the JVM now uses a new PlatformRegistry to select the appropriate platform implementation based on the installed security providers (Conscrypt, Bouncy Castle, OpenJSSE) or falls back to JDK 9/8/standard platforms. Additionally, GraalVM native image support is added via OkHttpFeature and GraalSvm configuration classes to enable ahead-of-time compilation.
okhttp/src/jvmMain/kotlin/okhttp3/internal · high confidence
Kotlin implementation of HttpLoggingInterceptor and LoggingEventListener
The HTTP logging interceptor and event listener have been reimplemented in Kotlin. The HttpLoggingInterceptor now supports redacting sensitive headers and query parameters, logs the total time of requests when buffering the body, and handles UnreadableResponseBody errors. The LoggingEventListener provides detailed logging of call events, including dispatcher queue status, DNS resolution, connection states, and request/response headers and bodies.
okhttp-logging-interceptor/src/main/kotlin · medium confidence
Migrated OkHttp tests to JUnit 5
The test suite in the \okhttp/src/jvmTest/kotlin/okhttp3\ directory has been migrated from JUnit 4 to JUnit 5. This change updates the test framework, replacing JUnit 4 annotations and rules with JUnit 5 equivalents (such as \@Test\ from \org.junit.jupiter.api.Test\ and \@RegisterExtension\), and introduces the \@StartStop\ annotation for managing the lifecycle of test fixtures like \MockWebServer\.
okhttp/src/jvmTest/kotlin/okhttp3 · high confidence
Published API signatures for TLS and URL connection modules
New API signature files have been added for the \okhttp-tls\ and \okhttp-urlconnection\ modules. The TLS module now exposes the public API for \Certificates\, \HandshakeCertificates\, and \HeldCertificate\ classes, including builder patterns and helper methods. The URL connection module now exposes the public API for \JavaNetAuthenticator\ and \JavaNetCookieJar\ classes. These changes establish the binary compatibility baseline for these modules.
okhttp-tls/api, okhttp-urlconnection/api · high confidence
Published API surface for the deprecated MockWebServer module
The public API for the deprecated MockWebServer module is now explicitly defined in the binary compatibility validator file. This change exposes the full public interface of the deprecated module, including the Dispatcher, MockResponse, MockWebServer, PushPromise, QueueDispatcher, RecordedRequest, and SocketPolicy classes, ensuring that the deprecated API surface is formally tracked for binary compatibility.
mockwebserver-deprecated/api · high confidence
Redesign of MockWebServer internal architecture and public API
The MockWebServer implementation has been significantly refactored, introducing a new \Dispatcher\ abstraction for handling requests and a \SocketHandler\ interface for duplex streams. The \RecordedRequest\ model has been expanded with new properties including \connectionIndex\, \exchangeIndex\, \handshake\, and \handshakeServerNames\ to provide more detailed request metadata. Additionally, the library now exposes \SocketEffect\ to allow tests to simulate adverse socket conditions like closing connections or stalling, and provides a \MockResponseBody\ interface for custom response bodies.
mockwebserver/src/main/kotlin · medium confidence
Refactor Server-Sent Events implementation into internal classes
The Server-Sent Events (SSE) implementation in the okhttp-sse module has been refactored by moving the core logic into new internal classes: RealEventSource and ServerSentEventReader. This change reorganizes the codebase by extracting the event processing and connection handling into dedicated internal components, improving code structure and maintainability without altering the public API.
okhttp-sse/src/main/kotlin/okhttp3/sse/internal · high confidence
Refactored build-logic into decoupled convention plugins and Gradle actions
The build system has been refactored into a set of decoupled convention plugins and Gradle build actions within the build-logic module. This includes new Kotlin files for managing OSGi/BND bundle building (BndBuildAction), Java module patching (JavaModules), and various Gradle conventions (base, JVM, testing, quality, publishing, Dokka). The refactoring introduces a static BndBuildAction to support Gradle Configuration Cache compatibility and replaces older plugin configurations with modern, reusable Gradle script conventions, improving build reliability and cacheability.
build-logic/src/main/kotlin · medium confidence
Stabilize the JUnit 4 API
A new API signature file (mockwebserver3-junit4.api) is introduced to establish a binary compatibility contract for the MockWebServerRule class. This change stabilizes the public interface for JUnit 4 users, ensuring that the API remains consistent across future updates.
mockwebserver-junit4/api · medium confidence
Updated Android test configuration for Robolectric
The Android host test environment has been updated to support Robolectric on API 35. A new Kotlin file, PublicSuffixTesting.android.kt, was added to configure the test runner and application context, while a corresponding robolectric.properties file was created to specify the SDK version and JDK requirements for the tests.
okhttp/src/androidHostTest · medium confidence
Updated Gradle wrapper to version 9.6.1
The Gradle wrapper has been updated to version 9.6.1, ensuring that the project uses this specific release of the Gradle build tool for all builds. This change updates the distribution URL and configuration in the wrapper properties to fetch and use Gradle 9.6.1.
gradle/wrapper · high confidence
Updated ProGuard configuration for OkHttp testing support
A new ProGuard rules file (okhttp3.pro) was added to the okhttp-testing-support module. This file suppresses warnings about optional classes, ensuring that the testing support library can be used in release builds without triggering ProGuard warnings about missing optional dependencies.
okhttp-testing-support/src/main/resources · low confidence
Test coverage
Add Android tests for SNI override functionality; Add fuzzing server test infrastructure; Added AllMainsTest to run all sample main methods; Added Android instrumentation tests for OkHttp; Added Android test for ALPN override; Added Android test for Let's Encrypt root certificate validation; Added Android-specific unit tests for logging, socket adapters, and initialization; Added Flaky and PlatformRule test support classes; Added HPACK test case submodule; Added HPACK test suite in Kotlin; Added HTTP client comparison tests for OkHttp, Java, Apache, and Jetty; Added HTTP/2 server test implementation in Kotlin; Added JVM tests for Call tag handling; Added Java module system tests; Added Kotlin test suite for MockWebServer; Added OSGi integration test for OkHttp modules; Added and migrated TLS test suite to JUnit 5 and Kotlin; Added container-based integration tests for OkHttp; Added native-image tests for resource loading and mock server integration; Added new test files for internal OkHttp components; Added new test suites for HttpLoggingInterceptor and LoggingEventListener; Added test coverage for PlatformRule; Added test data for URL parsing and public suffix validation; Added tests for DNS over HTTPS message parsing and integration; Added tests for MockWebServer3; Added tests for OkHttpClientTestRule; Added tests for SSE internal components; Added tests for public suffix and UTF-8 detection logic; Added tests for the new DER encoder and decoder; Added tests for the new Dns2 API, CompressionInterceptor, and OkHttp versioning; Added tests for the new zstd compression interceptor; Added unit tests for the Brotli and Gzip compression interceptors; Migrated okcurl tests from Java to Kotlin.
Dependencies
Migrate build system to Gradle Kotlin DSL and modernize dependencies
The project's build system has been fully converted to Gradle Kotlin DSL (\.kts\), introducing a new \build-logic\ convention plugin structure and a centralized \libs.versions.toml\ for dependency management. This migration includes updating the Android Gradle Plugin to version 9.1.1, Kotlin to 2.2.21, and refreshing a wide range of test and utility dependencies (such as JUnit 5, Robolectric, and Checkstyle) to their latest versions, while also enabling Gradle's configuration cache and type-safe project accessors.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 46 → 46 (+0.0)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.
Lenses
- Code Health 80 → 80 (+0.0)
- Architecture 100 → 100 (+0.1)
- Maturity 60 → 60 (+0.0)
- Readiness 34 → 34 (+0.0)
- Security 41 → 41 (+0.0)
Resolved (3)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- Off-boarding risk: anonymized user #1
- Off-boarding risk: anonymized user #2
New (3)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- Off-boarding risk: anonymized user #2
- Off-boarding risk: anonymized user #1
Architecture
- Unchanged — 0 containers · 2 contexts · 0 edges
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
square/okhttp was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 5 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 127cfe25168931aa600fff29c43f96d8d1dd480c — the exact code this score is about.
- Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer latest.