---
title: "HTTP - tune requests"
manual: "TYPO3 Explained"
version: "14.3"
permalink: "https://docs.typo3.org/permalink/t3coreapi:typo3confvars-http@14.3"
source: "Configuration/Typo3ConfVars/HTTP.rst"
rendered: "2026-10-01T15:20:05+00:00"
---

# HTTP - tune requests {#typo3confvars-http}

HTTP configuration to tune how TYPO3 behaves on HTTP requests made by TYPO3.
See [Guzzle documentation](https://docs.guzzlephp.org/en/latest/request-options.html)
for more background information on many of those settings.

> [!NOTE]
> The configuration values listed here are keys in the global PHP array
> `$GLOBALS['TYPO3_CONF_VARS']['HTTP']`.
>
> This variable can be set in one of the following files:
>
> -   [config/system/settings.php](https://docs.typo3.org/permalink/t3coreapi:typo3confvars-settings@14.3)
> -   [config/system/additional.php](https://docs.typo3.org/permalink/t3coreapi:typo3confvars-additional@14.3)

## allow_redirects {#typo3confvars-http-allow-redirects}

-   **allow_redirects**

    -   *Type:* mixed
    -   *Path:* $GLOBALS\['TYPO3_CONF_VARS'\]\['HTTP'\]\['allow_redirects'\]

    Mixed, set to false if you want to disallow redirects, or use it as an
    array to add more configuration values (see below).

    -   **strict**

        -   *Type:* bool
        -   *Default:* false
        -   *Path:* $GLOBALS\['TYPO3_CONF_VARS'\]\['HTTP'\]\['allow_redirects'\]\['strict'\]

        Whether to keep request method on redirects via status 301 and 302

        -   **`TRUE`**

            Strict RFC compliant redirects mean that POST redirect requests are
            sent as POST requests. This is needed for compatibility with
            [RFC 2616](http://www.faqs.org/rfcs/rfc2616))

        -   **`FALSE`**

            redirect POST requests with GET requests,
            needed for compatibility with most browsers

    -   **max**

        -   *Type:* int
        -   *Default:* 5
        -   *Path:* $GLOBALS\['TYPO3_CONF_VARS'\]\['HTTP'\]\['allow_redirects'\]\['max'\]

        Maximum number of tries before an exception is thrown.

## allowed_hosts {#typo3confvars-http-allowed-hosts}

-   **allowed_hosts**

    -   *Type:* array / null
    -   *Path:* $GLOBALS\['TYPO3_CONF_VARS'\]\['HTTP'\]\['allowed_hosts'\]

    This option is not passed on to guzzle. Instead, it configures
    an array of allowed hosts to interact with TYPO3.

    -   **webhooks**

        -   *Type:* array / null
        -   *Default:* null
        -   *Path:* $GLOBALS\['TYPO3_CONF_VARS'\]\['HTTP'\]\['allowed_hosts'\]\['webhooks'\]

        For now, the only supported array key is `webhooks` to configure an array
        of valid hostnames that webhooks of `EXT:webhooks` are allowed to connect to
        (see [forge#106229](https://forge.typo3.org/issues/106229) as a protection against DNS rebinding).

        Wildcards in the array values are allowed, like `*.example.com`.

        An empty array is allowed, but in that case it is better to actually remove
        the `EXT:webhooks` extension (all hosts are blocked).

        Setting this option to null (or having it unset) is the default,
        and will allow any connection.

## cert {#typo3confvars-http-cert}

-   **cert**

    -   *Type:* mixed
    -   *Default:* null
    -   *Path:* $GLOBALS\['TYPO3_CONF_VARS'\]\['HTTP'\]\['cert'\]

    Set to a string to specify the path to a file containing a
    PEM formatted client side certificate. See
    [Guzzle option cert](https://docs.guzzlephp.org/en/latest/request-options.html#cert)

## connect_timeout {#typo3confvars-http-connect-timeout}

-   **connect_timeout**

    -   *Type:* int
    -   *Default:* 10
    -   *Path:* $GLOBALS\['TYPO3_CONF_VARS'\]\['HTTP'\]\['connect_timeout'\]

    Default timeout for connection in seconds. Exception will be thrown if
    connecting to a remote host.

## proxy {#typo3confvars-http-proxy}

-   **proxy**

    -   *Type:* mixed
    -   *Default:* null
    -   *Path:* $GLOBALS\['TYPO3_CONF_VARS'\]\['HTTP'\]\['proxy'\]

    Enter a single proxy server as string, for example `'proxy.example.org'`

    Multiple proxies for different protocols can be added separately as an
    array as authentication and port; see
    [Guzzle documentation](https://docs.guzzlephp.org/en/latest/request-options.html#proxy)
    for details.

    The configuration with an array must be made in the
    `config/system/additional.php`; see
    [File config/system/additional.php](https://docs.typo3.org/permalink/t3coreapi:typo3confvars-additional@14.3) for
    details.

## ssl_key {#typo3confvars-http-ssl-key}

-   **ssl_key**

    -   *Type:* mixed
    -   *Default:* null
    -   *Path:* $GLOBALS\['TYPO3_CONF_VARS'\]\['HTTP'\]\['ssl_key'\]

    Local certificate and an optional passphrase, see
    [Guzzle option ssl-key](https://docs.guzzlephp.org/en/latest/request-options.html#ssl-key)

## timeout {#typo3confvars-http-timeout}

-   **timeout**

    -   *Type:* int
    -   *Default:* 0
    -   *Path:* $GLOBALS\['TYPO3_CONF_VARS'\]\['HTTP'\]\['timeout'\]

    Default timeout for whole request. Exception will be thrown if sending the
    request takes more than this number of seconds.

    Should be greater than the
    [connection timeout](https://docs.typo3.org/permalink/t3coreapi:typo3confvars-http-connect-timeout@14.3) or
    `0` to not set a limit.

## verify {#typo3confvars-http-verify}

-   **verify**

    -   *Type:* mixed
    -   *Default:* true
    -   *Path:* $GLOBALS\['TYPO3_CONF_VARS'\]\['HTTP'\]\['verify'\]

    Describes the SSL certificate verification behavior of a request, see
    [Guzzle option verify](https://docs.guzzlephp.org/en/latest/request-options.html#verify)

## version {#typo3confvars-http-version}

-   **version**

    -   *Type:* text
    -   *Default:* '1.1'
    -   *Path:* $GLOBALS\['TYPO3_CONF_VARS'\]\['HTTP'\]\['version'\]

    Default HTTP protocol version. Use either "1.0" or "1.1".
