A GET request is the message a browser, app or server sends to ask another machine for a resource identified by a web address. It is the oldest and most common method in the Hypertext Transfer Protocol (HTTP), the set of rules governing how pages, images and scripts move across the internet, and the current specification describes it as "the primary mechanism of information retrieval". For advertising, the method matters for a less obvious reason. Almost every tracking pixel, impression beacon, click redirect and email open counter is a GET request. The request asks for an image or a page, but its real cargo is the data written into the address.
How a GET request works
In a GET, the target is a URL such as https://ads.example.com/imp?cid=123&cb=8841. Everything after the question mark is the query string, a list of name and value pairs separated by ampersands. A GET normally carries no body. RFC 9110, the Internet Engineering Task Force (IETF) document defining HTTP semantics, states that content in a GET "has no generally defined semantics", so data travels in the URL or in headers.
The browser attaches any cookies it holds for the destination domain, a User-Agent string describing the browser and operating system, and often a Referer header naming the page that triggered the call. The receiving server also sees the IP address of the connection. A one-line image request thus delivers an identifier, a page address, a device profile and a rough location before any data has been deliberately added.
The specification classes GET as safe, meaning the client does not ask for any change of state on the server, and idempotent, meaning that repeating it should have the same intended effect as sending it once. Responses are cacheable by default. Safe does not mean inert. RFC 9110 takes its example from this industry: "a safe request initiated by selecting an advertisement on the Web will often have the side effect of charging an advertising account."
Where GET requests sit in the ad transaction
The classic tracking pixel is an HTML image tag pointing at a transparent 1x1 image. When the page or email renders, the browser issues a GET for the image and the server logs it. Meta's developer documentation gives the template for its image-based pixel as facebook.com/tr?id={pixel-id}&ev={standard-event}, with further values such as cd[value] and cd[currency] appended to the query string. The same documentation warns that the format cannot capture button clicks and is "subject to HTTP GET limits in sending custom data or long URLs".
Impression counting rests on the same plumbing. Under guidelines from the Interactive Advertising Bureau (IAB) and the Media Rating Council (MRC), the impression of record is an HTTP request from the device to a measurement endpoint, issued through an image tag, an inline frame or a script, and answered with a 1x1 beacon, a 302 redirect or the ad itself. A cached image would never reach the server a second time, so counters add a random string or timestamp to each URL, a practice known as cache-busting.
In the Video Ad Serving Template (VAST), Impression and TrackingEvents elements hold URLs that the player calls at the start, at each quartile and at completion, so buyer, seller and verification vendor can each count the same playback.
Cookie syncing chains GET requests together. A sync pixel loads, the first company reads its cookie and answers with an HTTP 302 redirect carrying its user ID in the query string. The browser follows with a second GET to the partner, which reads its own cookie and stores the pair.
Click tracking was long built as a series of redirects, each one a GET, between the click and the landing page. Google said that chain could add "hundreds of milliseconds" to arrival, before parallel tracking moved the tracker into the background, announced in October 2017 and made the default in 2018. Click identifiers such as Google's GCLID still travel as a parameter appended to the landing page URL.
Bidding is the exception. OpenRTB 2.6, the IAB Tech Lab's real-time bidding protocol, states that "HTTP POST is required for bid requests to accommodate greater payloads than HTTP GET". The notices that follow the auction are looser: "Win notices may be either POST or GET at the discretion of the exchange." The win notice URL (nurl), billing notice URL (burl) and loss notice URL (lurl) can carry macros such as ${AUCTION_PRICE}, which the exchange replaces with the clearing price before calling the address. A bidder may instead embed a tracking pixel in its markup to hear of a win "from the device itself".
Origin and evolution
GET predates every other HTTP method. According to RFC 9110, HTTP was introduced in 1990 and "began as a trivial mechanism for low-latency requests, with a single method (GET)". The 1991 version Tim Berners-Lee documented at CERN, later labelled HTTP/0.9, had no headers. RFC 1945, published in May 1996, recorded HTTP/1.0, with headers and the POST and HEAD methods. RFC 2616, in June 1999, defined HTTP/1.1 and set out the safe and idempotent properties in the form the web relied on for 15 years. RFC 7231 replaced it in June 2014. RFC 9110, published in June 2022, defines GET identically for HTTP/1.1, HTTP/2 and HTTP/3.
The IAB's 2004 measurement guidelines required client-initiated counting, making the device's own request the unit of currency. Alternatives followed. The World Wide Web Consortium (W3C) Beacon API, whose sendBeacon() call is specified to use POST, lets analytics data leave a closing page. Server-side tagging, which Google released in public beta on August 12, 2020, moved many vendor calls from the browser to a server the advertiser controls.
Why it matters for marketers
Most measurement arguments end at a request log. Discrepancies between an ad server and a demand-side platform (DSP) often come down to which GET was counted, when it fired and whether a cache, blocker or redirect intercepted it. The IAB and 4A's standard terms of February 2010 set a 10% threshold before such gaps trigger reconciliation.
The method has also become a legal object. A May 2026 complaint against OpenAI alleged that ChatGPT conversation titles reached Meta in a GET request to facebook.com/tr, alongside Facebook identifier cookies. In an April 2026 amicus brief to the Washington Supreme Court, the IAB contended that browser GET requests and server responses are automated device interactions, not person-to-person communications covered by the state's 1967 privacy act.
Limitations and disputes
Disclosure comes first. RFC 9110 warns that "URIs are intended to be shared, not secured" and that it is "unwise to include information within a URI that is sensitive, personally identifiable, or a risk to disclose". Servers and proxies log addresses, and the Referer header passes them on. Since Chrome 85 in August 2020, cross-origin requests send only the origin, not the full path and query string, according to Google's Chrome developer blog. Apple's Link Tracking Protection strips gclid and fbclid from links opened in Mail and Messages.
Size comes second. RFC 9110 recommends only that senders and recipients support URIs of at least 8,000 octets, and each server sets its own ceiling. Meta's documentation cites those GET limits as a constraint on how much custom data an image pixel can send.
Third, a GET does not prove a person. Because the method is safe, crawlers, link scanners and prefetchers fetch addresses freely. Apple Mail Privacy Protection, shipped on September 20, 2021, downloads remote images in the background by default, so a message can register as opened without being read. France's data protection authority, the CNIL, adopted a recommendation on March 12, 2026 that treats loading an email pixel as a read operation needing consent, with narrow exemptions.
Requests that are easy to log are also easy to block. One AdGuard filter list held more than 3,400 rules against first-party tracking subdomains, including 83 gtm and 42 sgtm entries, as of May 2026.
Not to be confused with
POST sends data in the request body rather than the address. It carries OpenRTB bid requests and sendBeacon() calls, and suits payloads too large or sensitive for a URL.
HEAD is identical to GET except that the server returns headers without a body.
Tracking pixel names the vehicle, not the request. An image pixel issues a GET, but a JavaScript tag can just as easily send a POST.
The get command in Google's site tag is a browser-side function that reads the client, session and click identifiers already stored on the page. It is not an HTTP method and sends nothing on its own.
Recent developments
RFC 10008, announced on June 16, 2026 and written by Julian Reschke, James Snell and Mike Bishop, defines a QUERY method that is safe and idempotent like GET but carries its parameters in a body, avoiding the length and logging problems of long query strings. It leaves existing pixels, which depend on GET, unchanged.
The Safari 27 beta, reviewed in July 2026, checks the destination IP address of outbound connections and can terminate them, reaching requests to Microsoft's bat.bing.com regardless of the subdomain a script loads from.
A study by IMDEA Networks, flagged on October 5, 2026, found that six of nine AI chatbot web clients sent conversation URLs, names, prompts or screenshots to outside firms.
California Governor Gavin Newsom signed SB 690 on September 30, 2026, ending private suits under the pen register provision of the California Invasion of Privacy Act (CIPA) for website and app conduct from January 1, 2027. Private wiretap claims under Sections 631 and 632, with their $5,000-per-violation damages formula, survive.
Timeline
- 1990 - HTTP introduced, with GET as its only method.
- 1991 - Tim Berners-Lee documents the protocol later known as HTTP/0.9.
- May 1996 - RFC 1945 records HTTP/1.0, adding headers, POST and HEAD.
- January 1997 - RFC 2068 places HTTP/1.1 on the IETF Standards Track.
- June 1999 - RFC 2616 revises HTTP/1.1 and defines safe and idempotent methods.
- 2004 - IAB measurement guidelines require client-initiated impression counting.
- July 29, 2008 - VAST released for public comment, standardising video tracking URLs.
- February 2010 - IAB and 4A's terms set a 10% discrepancy threshold.
- June 2014 - RFC 7231 replaces RFC 2616's semantics.
- December 2016 - OpenRTB 2.5 adds billing and loss notice URLs.
- October 2017 - Google announces parallel tracking for AdWords clicks.
- August 2020 - Chrome 85 trims cross-origin Referer headers to the origin by default.
- August 12, 2020 - Google server-side tagging enters public beta.
- September 20, 2021 - Apple Mail Privacy Protection ships with iOS 15.
- June 2022 - RFC 9110 published as the current definition of HTTP semantics.
- March 12, 2026 - CNIL adopts its final recommendation on email tracking pixels.
- April 10, 2026 - IAB files its amicus brief in Baker v. Seattle Children's Hospital.
- May 13, 2026 - Couture v. OpenAI filed in the Southern District of California.
- June 11, 2026 - OpenRTB 2.6-202606 released.
- June 16, 2026 - RFC 10008 defines the HTTP QUERY method.
- September 30, 2026 - SB 690 signed in California.
- October 5, 2026 - IMDEA Networks chatbot tracking study flagged.
Related PPC Land coverage
- Explaining count-on-download - How client-side requests to a measurement endpoint became the impression of record.
- Explaining VAST - The video template whose impression and quartile URLs are called by the player.
- Explaining cookie syncing - How sync pixels and 302 redirects map identifiers between ad tech companies.
- Explaining OpenRTB - The bidding protocol, including win, billing and loss notice URLs and price macros.
- Adwords with parallel tracking in 2018 - Google's move from redirect chains to background click tracking.
- Google's GCLID explainer shows how one parameter tracks every ad click - How the click identifier is appended to landing page URLs.
- Explaining server-side - What changes when measurement requests move from the browser to an operator's server.
- Explaining site tag - How the Google tag, Microsoft's UET and other site tags collect events.
- ChatGPT sued over secret data transfers to Meta and Google - A complaint built on captured GET requests to Meta's pixel endpoint.
- IAB backs Seattle Children's Hospital in Washington wiretap case that could reshape ad measurement - The IAB argument that GET requests are not private communications.
- Safari 26 tracking changes to impact marketing measurement - Link Tracking Protection and fingerprinting limits on query parameters.
- Explaining open rate - Why Apple's image prefetching broke email open measurement.
- CNIL's final rules on email tracking pixels are here - what changes - The French consent regime for email pixel requests.
- Ad blockers are now targeting server-side GTM subdomains by name - How filter lists match tracking requests on first-party hostnames.
- Safari 27 blocks LinkedIn and Bing ad trackers by IP address - Network-level blocking that ignores the requesting domain.
- 6 of 9 AI chatbots pass chat titles or links to trackers, IMDEA finds - Research on what tracking requests from AI chatbots carry.
- Newsom bans one kind of private web tracking lawsuit as claims near 4,000 - The California law narrowing private CIPA claims over web tracking.
Summary
Who. Browsers, apps, ad servers, exchanges, measurement vendors and analytics tags send GET requests. The IETF defines the method; the IAB, IAB Tech Lab and MRC define how advertising uses it; browser makers, regulators and courts set limits on what it may carry.
What. A GET request asks a server for the resource at a URL, carrying data in the query string and headers rather than a body. In advertising it is the transport for tracking pixels, impression and video beacons, cookie syncs, click redirects and, at the exchange's choice, win notices.
When. GET was HTTP's only method in 1990, was formalised in RFC 1945 in 1996 and RFC 2616 in 1999, and is currently defined by RFC 9110, published in June 2022. RFC 10008 added the related QUERY method in June 2026.
Where. It runs on web pages, in email clients, in video players and between servers, wherever one machine requests a resource from another over HTTP.
Why. A GET is the simplest way to make a device report an event: loading an address is enough to deliver identifiers, context and a timestamp. That simplicity makes it cheap to measure with, easy to block, prone to leaking whatever is written into the URL, and central to current privacy litigation.
Discussion