A public test server for HTTP & related protocols (similar to httpbin.org and badssl.com) but actively maintained, reliable & fast.
See the codePart of HTTP Toolkit: powerful tools for building, testing & debugging HTTP(S)
A public test server for HTTP & related protocols (similar to httpbin.org and badssl.com) but:
The endpoints provide everything from request introspection (to see what your client is actually sending) to unusual and even totally invalid cases (to test how your client handles weird data) so you can fully explore and test your network clients.
The hosted test server is available at testserver.host - try testserver.host/echo for example. See the documentation below for the full list of endpoints available for testing.
This hosted service is actively maintained and intended to be up at all times, but there's no specific SLA offered or suggested here right now, so there may be occasional intermittent downtime. If you'd like more control over this, you can also easily self-host a testserver locally:
docker run --rm -it -p 3000:3000 httptoolkit/testserver
Run curl -v localhost:3000/echo to test the HTTP echo endpoint. See the full self-hosting instructions below for more advanced setups.
The server includes custom endpoints for HTTP, WebSockets and TLS. These can be combined: e.g. specifying multiple TLS behaviours via the hostname (expired--http2.testserver.host) along with a chain of HTTP behaviours defined in the request path (/delay/1/error/reset). For full documentation of all endpoints, see the home page at testserver.host.
A public container image is published to Docker Hub (and mirrored to ghcr.io/httptoolkit/testserver):
docker run -p 3000:3000 httptoolkit/testserver
This is usable with no configuration, in which case TLS will be served with a dynamically generated local CA. There are various env vars that can be used for configuration including:
PORTS - comma-separated ports to listen on (default 3000)ROOT_DOMAIN - the domain being served (default localhost)ACME_PROVIDER - obtain real certificates via ACME: letsencrypt, zerossl or google (omit to use only the self-signed local CA)ACME_ACCOUNT_KEY - ACME account key in PEM format; required when ACME_PROVIDER is setCERT_CACHE_DIR - directory to persist issued certificates. This or CERT_STORE_S3_BUCKET (mutually exclusive) must be set if ACME is enabled to avoid accidentally hitting ACME rate limits.CERT_STORE_S3_BUCKET - use a shared, S3-compatible bucket for the cert store instead of CERT_CACHE_DIR (mutually exclusive with CERT_CACHE_DIR). Works with any S3-compatible host; the connection is read from the standard AWS variables AWS_ENDPOINT_URL_S3, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY (required), plus optional AWS_REGION (default auto)PROACTIVE_CERT_DOMAINS - comma-separated list of domains to proactively fetch certificates for on startupLOCAL_CA_KEY / LOCAL_CA_CERT - pin the local CA in PEM format; generated fresh if unsetDNS_SERVER - set true to run the built-in DNS server for wildcard (DNS-01) certs (needs UDP port 53)TRUST_PROXY_PROTOCOL - set true to honour PROXY protocol headers (for reading upstream client IP and connection information from behind a reverse proxy)METRICS_PORT - port to expose Prometheus metrics onFor advanced TLS cases, you will want:
LOCAL_CA_KEY and LOCAL_CA_CERT to the generated CA values.$CERT_CACHE_DIR as a volume to persist generated leaf & intermediate certs outside the container.CERT_STORE_S3_BUCKET to use a shared cert store on top of any S3-compatible provider instead.ACME_PROVIDER, create an account and provide the account key (as PEM) in ACME_ACCOUNT_KEY, and set CERT_CACHE_DIR (to a volume-mounted dir) or CERT_STORE_S3_BUCKET (and related S3 auth params) to persist the issued certificates.DNS_SERVER to true, expose UDP port 53, and configure the testserver as the nameserver for the _acme-challenge subdomain of its domain. If you use multiple instances, this requires use of S3 to coordinate challenge responses, or wildcard issuance will usually fail.expired.* it won't have an expired certificate ready. It will request a new short-lived certificate from the CA immediately to start that process, but it has to wait until this expires before it can use it. In the meantime, an expired certificate signed by the untrusted local CA will be used instead. Similarly for revoked.* - although the public cert will be revoked immediately, your client generally won't notice this immediately since revocation information nowadays is distributed asynchronously.315 followers · starred Jun 2025
A public test server for HTTP & related protocols (similar to httpbin.org and badssl.com) but actively maintained, reliable & fast.
See the codePart of HTTP Toolkit: powerful tools for building, testing & debugging HTTP(S)
A public test server for HTTP & related protocols (similar to httpbin.org and badssl.com) but:
The endpoints provide everything from request introspection (to see what your client is actually sending) to unusual and even totally invalid cases (to test how your client handles weird data) so you can fully explore and test your network clients.
The hosted test server is available at testserver.host - try testserver.host/echo for example. See the documentation below for the full list of endpoints available for testing.
This hosted service is actively maintained and intended to be up at all times, but there's no specific SLA offered or suggested here right now, so there may be occasional intermittent downtime. If you'd like more control over this, you can also easily self-host a testserver locally:
docker run --rm -it -p 3000:3000 httptoolkit/testserver
Run curl -v localhost:3000/echo to test the HTTP echo endpoint. See the full self-hosting instructions below for more advanced setups.
The server includes custom endpoints for HTTP, WebSockets and TLS. These can be combined: e.g. specifying multiple TLS behaviours via the hostname (expired--http2.testserver.host) along with a chain of HTTP behaviours defined in the request path (/delay/1/error/reset). For full documentation of all endpoints, see the home page at testserver.host.
A public container image is published to Docker Hub (and mirrored to ghcr.io/httptoolkit/testserver):
docker run -p 3000:3000 httptoolkit/testserver
This is usable with no configuration, in which case TLS will be served with a dynamically generated local CA. There are various env vars that can be used for configuration including:
PORTS - comma-separated ports to listen on (default 3000)ROOT_DOMAIN - the domain being served (default localhost)ACME_PROVIDER - obtain real certificates via ACME: letsencrypt, zerossl or google (omit to use only the self-signed local CA)ACME_ACCOUNT_KEY - ACME account key in PEM format; required when ACME_PROVIDER is setCERT_CACHE_DIR - directory to persist issued certificates. This or CERT_STORE_S3_BUCKET (mutually exclusive) must be set if ACME is enabled to avoid accidentally hitting ACME rate limits.CERT_STORE_S3_BUCKET - use a shared, S3-compatible bucket for the cert store instead of CERT_CACHE_DIR (mutually exclusive with CERT_CACHE_DIR). Works with any S3-compatible host; the connection is read from the standard AWS variables AWS_ENDPOINT_URL_S3, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY (required), plus optional AWS_REGION (default auto)PROACTIVE_CERT_DOMAINS - comma-separated list of domains to proactively fetch certificates for on startupLOCAL_CA_KEY / LOCAL_CA_CERT - pin the local CA in PEM format; generated fresh if unsetDNS_SERVER - set true to run the built-in DNS server for wildcard (DNS-01) certs (needs UDP port 53)TRUST_PROXY_PROTOCOL - set true to honour PROXY protocol headers (for reading upstream client IP and connection information from behind a reverse proxy)METRICS_PORT - port to expose Prometheus metrics onFor advanced TLS cases, you will want:
LOCAL_CA_KEY and LOCAL_CA_CERT to the generated CA values.$CERT_CACHE_DIR as a volume to persist generated leaf & intermediate certs outside the container.CERT_STORE_S3_BUCKET to use a shared cert store on top of any S3-compatible provider instead.ACME_PROVIDER, create an account and provide the account key (as PEM) in ACME_ACCOUNT_KEY, and set CERT_CACHE_DIR (to a volume-mounted dir) or CERT_STORE_S3_BUCKET (and related S3 auth params) to persist the issued certificates.DNS_SERVER to true, expose UDP port 53, and configure the testserver as the nameserver for the _acme-challenge subdomain of its domain. If you use multiple instances, this requires use of S3 to coordinate challenge responses, or wildcard issuance will usually fail.expired.* it won't have an expired certificate ready. It will request a new short-lived certificate from the CA immediately to start that process, but it has to wait until this expires before it can use it. In the meantime, an expired certificate signed by the untrusted local CA will be used instead. Similarly for revoked.* - although the public cert will be revoked immediately, your client generally won't notice this immediately since revocation information nowadays is distributed asynchronously.315 followers · starred Jun 2025