# http_response

*LSL event*

```lsl
http_response(key request_id, integer status, list metadata, string body)
```

- `key request_id`: Key matching the handle returned by the initiating llHTTPRequest call.
- `integer status`: Integer HTTP status code returned (such as 200 or 404).
- `list metadata`: A list of HTTP_* constants and response headers metadata.
- `string body`: String payload of the received response body.

Triggered when an HTTP response body is received for a pending request_id, or if the request fails or times out.

Triggered when task receives a response to one of its [llHTTPRequest](/functions/llHTTPRequest/)s

```lsl title="How to use" frame="terminal"
http_response(key request_id, integer status, list metadata, string body)
{

}
```

## Specification

Constant group [HTTPResponseError](/constants/groups/HTTPResponseError/):

```lsl
HTTP_BODY_TRUNCATED = 0
```

&lt;h3>Status 415 "Unsupported or unknown Content-Type"&lt;/h3>

The remote server did reply to your request but the Content-Type of the reply (such as XML, JSON, Atom, RSS, PLS) is not recognized by the LL server and so is not passed back to the script. You can assume that 415 means the server heard your request and did reply.

&lt;h3>Status 499&lt;/h3>

Besides the usual [HTTP status codes](https://en.wikipedia.org/wiki/List_of_HTTP_status_codes), SL implements a special **status** code 499. This code isn't generated by the remote web server but by SL's servers (see [Simulator_IP_Addresses](https://wiki.secondlife.com/wiki/Simulator_IP_Addresses)), it can indicate:

- Request timeout (60 seconds)
- SSL failure
- A space was present in the URL (escape your URL with [llEscapeURL](/functions/llEscapeURL/)).

&lt;h3>Status 502&lt;/h3>

The proxy server received an invalid response from an upstream server. This error occurs when you send an [llHTTPRequest](/functions/llHTTPRequest/) to an object in-world, and it does not reply with an [llHTTPResponse](/functions/llHTTPResponse/) [in time](/functions/llHTTPResponse/#caveats).

&lt;h3>Status 503&lt;/h3>

This error occurs when you send an [llHTTPRequest](/functions/llHTTPRequest/) to an object in-world, but the request was throttled before it reached the object. The throttle allows many requests per second to the set of scripts in the region that have the same owner. The response returns an HTTP Retry-After header to inform the caller how soon it may be attempted, but at present there is no way to access response headers in LSL.

<table>
	<tr>
		<th colspan="2">Constant</th>
		<th>Type</th>
		<th>Description</th>
	</tr>
	<tr>
		<td>[HTTP_BODY_TRUNCATED](/constants/HTTP_BODY_TRUNCATED/)</td>
		<td>0</td>
		<td>integer</td>
		<td>Truncation point in bytes</td>
	</tr>
</table>

## Caveats

- This events will be triggered in every script in the prim, not just in the [requesting](/functions/llHTTPRequest/) script.
- It is *not* guaranteed that there will be an [http_response](/events/http_response/) for every [llHTTPRequest](/functions/llHTTPRequest/)().
- If the script moves to a different region before the remote HTTP server can respond, the response will be lost. [https://lists.secondlife.com/pipermail/secondlifescripters/2011-August/006309.html](https://lists.secondlife.com/pipermail/secondlifescripters/2011-August/006309.html)

## Examples

<details open>
<summary>Example 1</summary>

```lsl collapse={1-7}
key http_request_id;

default
{
    state_entry()
    {
        http_request_id = llHTTPRequest("url", [], "");
    }

    http_response(key request_id, integer status, list metadata, string body)
    {
        if (request_id == http_request_id)
        {
            llSetText(body, <0,0,1>, 1);
        }
    }
}
```

</details>

<details>
<summary>To parse POST content:</summary>

```lsl
string get_post_value(string content, string returns)
{
//  this parses application/x-www-form-urlencoded POST data

//  for instance if the webserver posts 'data1=hi&data2=blah' then
//  calling get_post_value("data1=hi&data2=blah","data1"); would return "hi"
//  written by MichaelRyan Allen, Unrevoked Clarity

    list params =  llParseString2List(content,["&"],[]);
    integer index = ~llGetListLength(params);

    list keys;// = [];
    list values;// = [];

    // start with -length and end with -1
    while (++index)
    {
        list parsedParams =  llParseString2List(llList2String(params, index), ["="], []);
        keys += llUnescapeURL(llList2String(parsedParams, 0));
        values += llUnescapeURL(llList2String(parsedParams, 1));
    }

    integer found = llListFindList(keys, [returns]);
    if(~found)
        return llList2String(values, found);
//  else
        return "";
}
```

</details>

<details>
<summary>Another Example:</summary>

:::note
Remember to release URLs that you have requested! They are region resources just like prims, and it is possible to use them all and break other scripts.
:::

```lsl collapse={1-76, 96-103}
string url;
key urlRequestId;
key selfCheckRequestId;

request_url()
{
    llReleaseURL(url);
    url = "";

    urlRequestId = llRequestURL();
}

throw_exception(string inputString)
{
    key owner = llGetOwner();
    llInstantMessage(owner, inputString);

    // yeah, bad way to handle exceptions by restarting.
    // However this is just a demo script...

    llResetScript();
}

default
{
    on_rez(integer start_param)
    {
        llResetScript();
    }

    changed(integer change)
    {
        if (change & (CHANGED_OWNER | CHANGED_INVENTORY))
        {
            llReleaseURL(url);
            url = "";

            llResetScript();
        }

        if (change & (CHANGED_REGION | CHANGED_REGION_START | CHANGED_TELEPORT))
            request_url();
    }

    state_entry()
    {
        request_url();
    }

    http_request(key id, string method, string body)
    {
        integer responseStatus = 400;
        string responseBody = "Unsupported method";

        if (method == URL_REQUEST_DENIED)
            throw_exception("The following error occurred while attempting to get a free URL for this device:\n \n" + body);

        else if (method == URL_REQUEST_GRANTED)
        {
            url = body;
            key owner = llGetOwner();
            llLoadURL(owner, "Click to visit my URL!", url);

            // check every 5 mins for dropped URL
            llSetTimerEvent(300.0);
        }
        else if (method == "GET")
        {
            responseStatus = 200;
            responseBody = "Hello world!";
        }
        // else if (method == "POST") ...;
        // else if (method == "PUT") ...;
        // else if (method == "DELETE") { responseStatus = 403; responseBody = "forbidden"; }

        llHTTPResponse(id, responseStatus, responseBody);
    }

    http_response(key id, integer status, list metaData, string body)
    {
        if (id == selfCheckRequestId)
        {
            // If you're not usually doing this,
            // now is a good time to get used to doing it!
            selfCheckRequestId = NULL_KEY;

            if (status != 200)
                request_url();
        }

        else if (id == NULL_KEY)
            throw_exception("Too many HTTP requests too fast!");
    }

    timer()
    {
        selfCheckRequestId = llHTTPRequest(url,
                                [HTTP_METHOD, "GET",
                                    HTTP_VERBOSE_THROTTLE, FALSE,
                                    HTTP_BODY_MAXLENGTH, 16384],
                                "");
    }
}
```

</details>

## Notes

#### Parsing Problems

If for some reason while using [llHTTPRequest](/functions/llHTTPRequest/)/[http_response](/events/http_response/) you are unable to parse a known good RSS feed or some other form of web contents, you will need to work around it outside of Second Life. This is unlikely to change in the near future since checking the headers requires more overhead at the simulator level.

#### Unicode

When serving content with UTF-8 characters be sure your server sets the outgoing `Content-Type` header so that it includes `charset=utf-8` otherwise it will be interpreted incorrectly. See [W3C:Setting the HTTP charset parameter](http://www.w3.org/International/O-HTTP-charset) for further details.

#### Request Headers

<table>
	<caption>Headers sent by the simulator in the course of calling [llHTTPRequest](/functions/llHTTPRequest/).</caption>
	<tr>
		<th>Header</th>
		<th>Description</th>
		<th>Example data</th>
	</tr>
	<tr>
		<td>Connection</td>
		<td>Connection options</td>
		<td>close</td>
	</tr>
	<tr>
		<td>Cache-Control</td>
		<td>Maximum response age accepted.</td>
		<td>max-age=259200</td>
	</tr>
	<tr>
		<td>X-Forwarded-For</td>
		<td>Used to show the IP address connected to through proxies.</td>
		<td>127.0.0.1</td>
	</tr>
	<tr>
		<td>Via</td>
		<td>Shows the recipients and protocols used between the User Agent and the server.</td>
		<td>1.1 sim10115.agni.lindenlab.com:3128 (squid/2.7.STABLE9)</td>
	</tr>
	<tr>
		<td>Content-Length</td>
		<td>The size of the entity-body, in decimal number of octets.</td>
		<td>17</td>
	</tr>
	<tr>
		<td>Pragma</td>
		<td>The message should be forwarded to the server, even if it has a cached version of the data.</td>
		<td>no-cache</td>
	</tr>
	<tr>
		<td>X-SecondLife-Shard</td>
		<td>The environment the object is in. "Production" is the main grid and "Testing" is the preview grid</td>
		<td>Production</td>
	</tr>
	<tr>
		<td>X-SecondLife-Region</td>
		<td>The name of the region the object is in, along with the global coordinates of the region's south-west corner</td>
		<td>Jin Ho (264448, 233984)</td>
	</tr>
	<tr>
		<td>X-SecondLife-Owner-Name</td>
		<td>[Legacy name](https://wiki.secondlife.com/wiki/Category:LSL_Avatar/Name) of the owner of the object</td>
		<td>Zeb Wyler</td>
	</tr>
	<tr>
		<td>X-SecondLife-Owner-Key</td>
		<td>[UUID](https://wiki.secondlife.com/wiki/UUID) of the owner of the object</td>
		<td>01234567-89ab-cdef-0123-456789abcdef</td>
	</tr>
	<tr>
		<td>X-SecondLife-Object-Name</td>
		<td>The name of the object containing the script</td>
		<td>Object</td>
	</tr>
	<tr>
		<td>X-SecondLife-Object-Key</td>
		<td>The key of the object containing the script</td>
		<td>01234567-89ab-cdef-0123-456789abcdef</td>
	</tr>
	<tr>
		<td>X-SecondLife-Local-Velocity</td>
		<td>The velocity of the object</td>
		<td>0.000000, 0.000000, 0.000000</td>
	</tr>
	<tr>
		<td>X-SecondLife-Local-Rotation</td>
		<td>The rotation of the object containing the script</td>
		<td>0.000000, 0.000000, 0.000000, 1.000000</td>
	</tr>
	<tr>
		<td>X-SecondLife-Local-Position</td>
		<td>The position of the object within the region</td>
		<td>(173.009827, 75.551231, 60.950001)</td>
	</tr>
	<tr>
		<td>User-Agent</td>
		<td>The user-agent header sent by LSL Scripts. Contains Server version.</td>
		<td>Second Life LSL/16.05.24.315768 (http://secondlife.com)</td>
	</tr>
	<tr>
		<td>Content-Type</td>
		<td>The media type of the entity body.</td>
		<td>text/plain; charset=utf-8</td>
	</tr>
	<tr>
		<td>Accept-Charset</td>
		<td>Acceptable character sets from the server. Q being the quality expected when sending the different character sets.</td>
		<td>utf-8;q=1.0, \*;q=0.5</td>
	</tr>
	<tr>
		<td>Accept</td>
		<td>Media types the server will accept.</td>
		<td>text/\*, application/xhtml+xml, application/atom+xml, application/json, application/xml, application/llsd+xml, application/x-javascript, application/javascript, application/x-www-form-urlencoded, application/rss+xml</td>
	</tr>
	<tr>
		<td>Accept-Encoding</td>
		<td>Acceptable content encodings for the server.</td>
		<td>deflate, gzip</td>
	</tr>
	<tr>
		<td>Host</td>
		<td>The internet host being requested.</td>
		<td>secondlife.com</td>
	</tr>
	<tr>
		<td colspan="3">

			:::note
			Certain server environments (CGI) place headers into variables by capitalizing the entire name, replacing dashes with underscores, and prefixing the name with "HTTP\_", e.g. "X-SecondLife-Object-Name" becomes "HTTP_X_SECONDLIFE_OBJECT_NAME". This depends solely on the HTTP server used to process the request and cannot be controlled via LSL.
			:::

			:::note
			[RFC 2616 § 4.2](https://datatracker.ietf.org/doc/html/rfc2616#section-4.2) defines HTTP header field names as case-insensitive. The capitalization of header field names shown above is not guaranteed; for example, "X-SecondLife-Object-Name" may be received as "X-Secondlife-Object-Name". See [BUG-5094](https://jira.secondlife.com/browse/BUG-5094) for an instance of ISPs recapitalizing headers. This behavior was also observed when testing in 2026.
			:::

		</td>
		<td></td>
		<td></td>
	</tr>
</table>

## See also

### Functions

- [llHTTPRequest](/functions/llHTTPRequest/)
- [llHTTPResponse](/functions/llHTTPResponse/)

---

*Source: [Http response](https://wiki.secondlife.com/wiki/Http_response) on the Second Life Wiki. Content from the Second Life Wiki articles Http response (revision 1216214, 2024-02-17) and Template:LSL Constants/HTTP Headers (revision 1218827, 2026-05-04), CC BY-SA 3.0.*

---

From lsl.dev: https://lsl.dev/events/http_response/
