---
title: "URI arguments and reserved keywords"
manual: "TYPO3 Explained"
version: "13.4"
permalink: "https://docs.typo3.org/permalink/t3coreapi:extbase-arguments@13.4"
source: "ExtensionArchitecture/Extbase/Reference/UriArguments.rst"
rendered: "2026-10-05T17:28:20+00:00"
---

# URI arguments and reserved keywords {#extbase-arguments}

Extbase uses special URI arguments to pass variables
to Controller arguments and the framework itself.

Extbase uses a prefixed URI argument scheme that relies
on plugin configuration.

For example, the example extension `EXT:blog_example` would use:

```plaintext
// Linebreaks just for readability.
https://example.org/blog/?tx_blogexample_bloglist[action]=show
&tx_blogexample_bloglist[controller]=Post
&tx_blogexample_bloglist[post]=4711
&cHash=...

// Actually, the [] parameters are often URI encoded, so this is emitted:
https://example.org/blog/?tx_blogexample_bloglist%5Baction%5D=show
&tx_blogexample_bloglist%5Bcontroller%5D=Post
&tx_blogexample_bloglist%5Bpost%5D=4711
&cHash=...
```

as the created URI to execute the `showAction` of the Controller `PostController`
within the plugin `BlogList`.

The following arguments are evaluated:

-   **`tx_(extensionName)_(pluginName)[action]`:**

    Controller action to execute

-   **`tx_(extensionName)_(pluginName)[controller]`**

    Controller containing the action

-   **`tx_(extensionName)_(pluginName)[format]`**

    Output format (usually `html`, can also be `json` or custom types)

-   **`cHash`**

    the cHash always gets calculated to validate that the URI is allowed to be called. (see [Caching variants - or: What is a "cache hash"?](https://docs.typo3.org/permalink/t3coreapi:chash@13.4))

Any other argument will be passed along to the controller action and can be
retrieved via `$this->request->getArgument()`. Usually this is auto-wired
by the automatic parameter mapping of Extbase.

These URI arguments can also be used for the routing configuration, see
[Extbase plugin enhancer](https://docs.typo3.org/permalink/t3coreapi:routing-extbase-plugin-enhancer@13.4).

> [!WARNING]
> The listed keys `action`, `controller` and `format` are reserved keywords.
> Never use these as custom argument names to your controller actions,
> so instead of `<f:uri.action action="new" arguments="{format: someVariable}">`
> you should use `<f:uri.action action="new" arguments="{customFormat: someVariable}">`.
> Else, using an argument like this would lead to TYPO3 exceptions of unresolvable
> Fluid template files!

When submitting a HTML `<form>`, the same URI arguments will be part of
a HTTP POST request, with some more special ones:

> -   **`tx_(extensionName)_(pluginName)[__referrer]`**
>
>     An array with information
>     of the referring call (subkeys: `@extension`, `@controller`, `@action`,
>
> `arguments` (hashed), `@request` (json)

-   **`tx_(extensionName)_(pluginName)[__trustedProperties]`**

    List of properties to be submitted to an action (hashed and secured)

These two keys are also regarded as reserved keywords. Generally, you should
avoid custom arguments interfering with either the `@...` or `__...` prefix
notation.
