libchttpx is a compact HTTP/2 server library for C on Linux and macOS. It provides an App-based runtime, routing, middleware, request parsing, JSON binding and responses, uploads, request-scoped memory, CORS, cookies, i18n, logging, rate limiting, and graceful shutdown while keeping a direct C-style API.
The library is designed so handlers contain application logic instead of repetitive HTTP plumbing.
- Linux and macOS support
- multiple independent HTTP servers inside one
cHTTPX_App - local direct server-to-server calls and remote HTTP/HTTPS calls
- route groups and
{parameter}paths - global, router, and route middleware with before/after phases
- typed path/query accessors and URL decoding
- request-scoped allocation, deferred cleanup, and named contexts
- JSON parsing, validation, normalization, binding, and builder responses
- multipart forms, multiple uploads, upload policies, and temporary-file cleanup
- request IDs and
Accept-Languagenegotiation - CORS, cookies, logging callbacks, and rate limiting
- configurable gzip response compression with
Accept-Encodingnegotiation - optional built-in metrics with thread-safe snapshots and a Prometheus exporter
- first-class HTTP/2 Server-Sent Events with retry, heartbeat, and disconnect handling
- configurable server limits and graceful shutdown
cHTTPX_ResFile()is disk-backed and streams files in bounded 64 KiB chunks, so multi-gigabyte responses do not require an equally large RAM allocation. Generic zero-copysendfile()output is still not implemented.
For Debian/Ubuntu on amd64, add the libchttpx APT repository once:
curl -fsSL https://netcorelink.github.io/libchttpx/apt/libchttpx.sources \
| sudo tee /etc/apt/sources.list.d/libchttpx.sources >/dev/null
sudo apt update
sudo apt install libchttpx-devAfter that, libchttpx updates are installed through the normal APT flow:
sudo apt update
sudo apt upgradeRemove the package:
sudo apt remove libchttpx-devRemove the repository itself:
sudo rm /etc/apt/sources.list.d/libchttpx.sources
sudo apt updateThe current repository uses Trusted: yes, so users do not need to install a separate GPG key. Package signing can be added later.
Compile an application after installation:
gcc server.c -o server $(pkg-config --cflags --libs libchttpx)Native packages are also attached to GitHub Releases:
Fedora / RHEL and compatible RPM distributions
sudo dnf install ./libchttpx-dev-*.rpmArch Linux
sudo pacman -U ./libchttpx-dev-*.pkg.tar.zstAlpine Linux
sudo apk add --allow-untrusted ./libchttpx-dev_*.apkDownload the package for your distribution from GitHub Releases.
curl -s https://raw.githubusercontent.com/netcorelink/libchttpx/main/scripts/install.sh | sudo shPull the published runtime image:
docker pull noneandundefined/libchttpx:latestThe image contains the installed shared library, headers, pkg-config metadata, and the cJSON, zlib, and nghttp2 runtimes.
FROM noneandundefined/libchttpx:latest
COPY my-server /usr/local/bin/my-server
CMD ["/usr/local/bin/my-server"]Optional native TLS/HTTPS support uses OpenSSL. See Native TLS / HTTPS for server certificates, HTTPS remote calls, custom CA verification, and mTLS.
Response compression is included in the standard build. Applications enable gzip at runtime with cHTTPX_CompressionUse(). See Response compression.
Detailed documentation is split by functionality:
- Documentation index
- App runtime, multiple servers, AppRemote, Call and CallEx
- Server configuration, limits, lifecycle and error codes
- Native TLS / HTTPS
- Response compression
- Metrics and Prometheus exporter
- Routing and route groups
- Middleware
- Requests, headers, params, queries and body access
- Responses and ownership
- JSON binding, validation and JSON builder
- Request-scoped memory and contexts
- Uploads, multipart forms and MIME helpers
- CORS
- Cookies
- Request IDs and i18n
- Logging
- Rate limiting
- Server-Sent Events
- WebSocket API — experimental
BSD 3-Clause. See LICENSE.