XMLHttpRequest - Web APIs | MDN

archived 26 Dec 2025 05:06:06 UTC

XMLHttpRequest

Baseline Widely available *
This feature is well established and works across many devices and browser versions. It’s been available across browsers since ⁨July 2015⁩.
* Some parts of this feature may have varying levels of support.
Note: This feature is available in Web Workers, except for Service Workers.
XMLHttpRequest (XHR) objects are used to interact with servers. You can retrieve data from a URL without having to do a full page refresh. This enables a Web page to update just part of a page without disrupting what the user is doing.
EventTarget XMLHttpRequestEventTarget XMLHttpRequest
Despite its name, XMLHttpRequest can be used to retrieve any type of data, not just XML.
If your communication needs to involve receiving event data or message data from a server, consider using server-sent events through the EventSource interface. For full-duplex communication, WebSockets may be a better choice.

Constructor

XMLHttpRequest()
The constructor initializes an XMLHttpRequest. It must be called before any other method calls.

Instance properties

This interface also inherits properties of XMLHttpRequestEventTarget and of EventTarget.
XMLHttpRequest.readyState Read only
Returns a number representing the state of the request.
XMLHttpRequest.response Read only
Returns an ArrayBuffer, a Blob, a Document, a JavaScript object, or a string, depending on the value of XMLHttpRequest.responseType, that contains the response entity body.
XMLHttpRequest.responseText Read only
Returns a string that contains the response to the request as text, or null if the request was unsuccessful or has not yet been sent.
XMLHttpRequest.responseType
Specifies the type of the response.
XMLHttpRequest.responseURL Read only
Returns the serialized URL of the response or the empty string if the URL is null.
XMLHttpRequest.responseXML Read only
Returns a Document containing the response to the request, or null if the request was unsuccessful, has not yet been sent, or cannot be parsed as XML or HTML. Not available in Web Workers.
XMLHttpRequest.status Read only
Returns the HTTP response status code of the request.
XMLHttpRequest.statusText Read only
Returns a string containing the response string returned by the HTTP server. Unlike XMLHttpRequest.status, this includes the entire text of the response message ("OK", for example).
Note: According to the HTTP/2 specification RFC 7540, section 8.1.2.4: Response Pseudo-Header Fields​ (external), HTTP/2 does not define a way to carry the version or reason phrase that is included in an HTTP/1.1 status line.
XMLHttpRequest.timeout
The time in milliseconds a request can take before automatically being terminated.
XMLHttpRequest.upload Read only
A XMLHttpRequestUpload representing the upload process.
XMLHttpRequest.withCredentials
Returns true if cross-site Access-Control requests should be made using credentials such as cookies or authorization headers; otherwise false.

Non-standard properties

XMLHttpRequest.mozAnon Read only Non-standard
A boolean. If true, the request will be sent without cookie and authentication headers.
XMLHttpRequest.mozSystem Read only Non-standard
A boolean. If true, the same origin policy will not be enforced on the request.

Instance methods

XMLHttpRequest.abort()
Aborts the request if it has already been sent.
XMLHttpRequest.getAllResponseHeaders()
Returns all the response headers, separated by CRLF, as a string, or null if no response has been received.
XMLHttpRequest.getResponseHeader()
Returns the string containing the text of the specified header, or null if either the response has not yet been received or the header doesn't exist in the response.
XMLHttpRequest.open()
Initializes a request.
XMLHttpRequest.overrideMimeType()
Overrides the MIME type returned by the server.
XMLHttpRequest.send()
Sends the request. If the request is asynchronous (which is the default), this method returns as soon as the request is sent.
XMLHttpRequest.setAttributionReporting() Secure context Deprecated
Indicates that you want the request's response to be able to register an attribution source or trigger event.
XMLHttpRequest.setPrivateToken() Experimental
Adds private state token information to an XMLHttpRequest call, to initiate private state token operations.
XMLHttpRequest.setRequestHeader()
Sets the value of an HTTP request header. You must call setRequestHeader() after open(), but before send().

Events

This interface also inherits events of XMLHttpRequestEventTarget.
readystatechange
Fired whenever the readyState property changes. Also available via the onreadystatechange event handler property.

Specifications

Specification
XMLHttpRequest
# interface-xmlhttprequest​ (external)

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
XMLHttpRequest
XMLHttpRequest() constructor
abort
abort event
Authorization header removed from cross-origin redirects
error event
getAllResponseHeaders
Header names returned in all lower case
getResponseHeader
load event
loadend event
loadstart event
open
overrideMimeType
progress event
readyState
readystatechange event
response
responseText
responseType
responseType.arraybuffer_value
responseType.blob_value
responseType.document_value
responseType.json_value
responseURL
responseXML
send
ArrayBufferView as parameter to send()
ArrayBuffer as parameter to send()
Blob as parameter to send()
FormData as parameter to send()
URLSearchParams as parameter to send()
setAttributionReporting
Deprecated
setPrivateToken
Experimental
setRequestHeader
status
statusText
timeout
timeout event
upload
withCredentials
Available in workers

Legend

Tip: you can click/tap on a cell for more information.
Full support Full support
Partial support Partial support
No support No support
⁨Experimental⁩. Expect behavior to change in the future.
⁨Deprecated⁩. Not for use in new websites.
See implementation notes.
Has more compatibility info.

See also

Help improve MDN

Learn how to contribute
This page was last modified on by MDN contributors.
0%
10%
20%
30%
40%
50%
60%
70%
80%
90%
100%