Library / SDK
sindresorhus/got avatar
sindresorhus/got

Got: a Node.js HTTP client that ships with retries, hooks and HTTP/2

🌐 Human-friendly and powerful HTTP request library for Node.js

14,949 stars1,003 forksTypeScriptMIT

At a glance

What is it?
Got is an ESM-only HTTP request library for Node.js 22 and later, maintained by Sindre Sorhus. It is the right pick when you need retry policy, pagination or HTTP/2 built in, and the wrong pick if you still ship CommonJS or run in a browser.
Who is it for?
Adopt Got if you are on Node.js 22 or later, your project is already ESM, and you want retries, hooks, pagination and HTTP/2 in one dependency rather than assembled from fetch plus helpers. Do not adopt it if you ship CommonJS, target browsers, or are still on Got v11, which the README states is no longer maintained and receives no backports.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 10 days ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What Got solves for Node.js services

Node's built-in http module gives you a socket and a stream. Everything above that, such as following redirects, decompressing responses, retrying a failed request with backoff, or paging through a cursor API, is left to you. Got fills that gap for server-side Node.js code. The README describes it as a human-friendly and powerful HTTP request library, and the documentation index lists the pieces it covers: a Promise API, a Stream API, a Pagination API, advanced timeout handling, retries on failure, errors with metadata, hooks, instances and plugins. The audience is a backend or CLI developer who wants those behaviours configured through one options object instead of written by hand. The README also names the plugins built on top of it, including got4aws for AWS v4 signed APIs, gh-got for the GitHub API, gl-got for GitLab, gotql for GraphQL, got-fetch for a fetch-shaped interface, got-scraping for scraping and got-ssrf for protecting server-side requests against SSRF. That list is the clearest signal of the intended use: long-running Node processes talking to third-party HTTP APIs.

How Got's request pipeline is put together

The package.json shows a dependency set rather than one monolith. cacheable-request handles HTTP caching, keyv backs the cache store, decompress-response handles compressed bodies, responselike models responses, lowercase-keys normalises header casing, byte-counter and chunk-data deal with byte accounting, and @sindresorhus/is plus type-fest supply runtime and compile-time type checks. The package is marked sideEffects false and exports a single entry, dist/source/index.js, with types at dist/source/index.d.ts. The source directory is TypeScript, and the build script is del-cli dist followed by tsc, so what npm publishes is compiled output, not the sources. Two behaviours are worth knowing before you write code. First, the README states that Got retries on failure by default, and that you disable it by setting options.retry.limit to 0. Second, JSON is a first-class path: the json option handles the payload, and the promise exposes a .json<T>() method that returns Promise<T> for typed access. Hooks and instances sit on top of that pipeline, which is how you attach cross-cutting concerns such as auth headers or logging without wrapping every call site.

Installing Got and making a first JSON request

Installation is a single npm command, and the README gives it directly.

bash
npm install got

The package is native ESM and, per the README, no longer provides a CommonJS export. The package.json confirms this with a type field of module and an exports map whose default target is ./dist/source/index.js. The engines field requires Node.js 22 or later. The README is blunt about the consequence: if your project uses CommonJS, you have to convert to ESM, and it asks that you not open issues about CommonJS or ESM. A minimal JSON POST looks like this, taken from the README's JSON mode example.

js
import got from 'got';

const {data} = await got.post('https://httpbin.org/anything', {
	json: {
		hello: 'world'
	}
}).json();

console.log(data);
//=> {"hello": "world"}

The json option serialises the body and sets the appropriate content type; .json() parses the response and returns a promise of the parsed value. You should see the object you sent echoed back by the endpoint. To turn off the default retry behaviour, the README points at options.retry.limit set to 0. The README also links a quick start guide under documentation/quick-start.md and a Tips page under documentation/tips.md, which is where the project expects you to look next.

Where Got is the wrong tool

The README opens with a redirect that is unusual for a project page: it says you probably want Ky instead, by the same people, smaller, working in the browser too, and more stable because it is built on Fetch. That is the maintainers telling you the default answer for most new code. Got's own comparison table marks browser support as absent for Got and present for Ky, axios, superagent and node-fetch. So if your code has to run in a browser, or in an edge runtime without Node's http stack, Got is not the library you want. The second hard boundary is module format. There is no CommonJS export, and the README explicitly refuses CommonJS questions as issues, which means a CommonJS codebase is looking at an ESM conversion before it can adopt Got at all. The third is version drift. The README states that Got v11 is no longer maintained and that backport requests will not be accepted, so a project pinned to v11 is on an unsupported line. Finally, the default retry policy is a behaviour, not a neutral default: retrying a request that is not idempotent can duplicate a write on the server unless you set options.retry.limit to 0 or restrict the methods that retry.

Got compared with Axios and with plain fetch

Axios is the closest alternative in the same server-side space. The README's comparison table lists HTTP/2 support for Got, Ky and superagent, and marks it absent for node-fetch and axios; browser support is the mirror image, present for axios and absent for Got. That is the real difference in approach rather than a feature checklist. Axios is designed to run in both browser and Node, which shapes its API around XHR-compatible behaviour and keeps it on HTTP/1.1. Got is designed for Node only and takes advantage of Node-specific machinery: HTTP/2, Unix domain sockets, proxy support, an RFC 7234 compliant cache, the Diagnostics Channel and a Stream API that the table marks as Node.js only for node-fetch and absent for Ky. If your code is one codebase serving both a browser bundle and a server, Axios removes a split. If your code is a server process talking to APIs and you want HTTP/2, caching and retries without adding four packages, Got is the more direct fit. The README also links migration guides for Request, Axios and Node.js, so moving from Axios is a documented path rather than a rewrite from scratch.

Maintenance, licence and the cost of upgrading

The repository is not archived and the last push was on 2026-09-20, which is one day before this article's frame of reference, so the project is being worked on now. The release history backs that up: v16.0.0 landed on 2026-08-30, v15.1.0 on 2026-07-02 and v15.0.7 on 2026-06-28. A major version bump in the last month is the main upgrade cost to plan for. The README carries migration guides for Request, Axios and Node.js, but those live under documentation/migration-guides and the README does not document a rollback procedure, so the practical step is to read the v16 release notes before moving a production service. The licence is MIT, stated in both the README metadata and the license file at the repository root. MIT is permissive: it allows use, modification and redistribution with the copyright notice and permission notice retained. That is a description of the licence text, not legal advice; if your organisation has a policy on dependency licences, run it through that process. One more cost to note is transitive. Got depends on ten packages, including cacheable-request, keyv and decompress-response, so a security review has to cover those as well as Got itself.

Editorial conclusion

Adopt Got if you are on Node.js 22 or later, your project is already ESM, and you want retries, hooks, pagination and HTTP/2 in one dependency rather than assembled from fetch plus helpers. Do not adopt it if you ship CommonJS, target browsers, or are still on Got v11, which the README states is no longer maintained and receives no backports. Before committing, verify three things against your own environment: that your Node version satisfies the engines field of >=22, that your build pipeline resolves the exports map to dist/source/index.js rather than looking for a CommonJS entry, and that the default retry behaviour will not duplicate any request that is not idempotent. The README itself points most casual users at Ky instead, so treat Got as the choice for server-side Node work that needs the extra surface.

Frequently asked questions

What is sindresorhus/got?

It is an HTTP request library for Node.js, described in its README as human-friendly and powerful, with a Promise API, a Stream API, retries, hooks and HTTP/2 support. It is published on npm as got and licensed under MIT.

How do I install Got?

The README gives a single command, npm install got. The package requires Node.js 22 or later according to its engines field, and it is native ESM with no CommonJS export.

Does Got work with CommonJS?

No. The README states the package is native ESM and no longer provides a CommonJS export, and it asks users not to open issues about CommonJS or ESM. A CommonJS project has to convert to ESM first.

How do I turn off Got's automatic retries?

The README states that Got retries on failure by default and that setting options.retry.limit to 0 disables it. That matters for requests that are not idempotent, where a retry can duplicate a write.

How does Got handle JSON payloads?

Got has a dedicated json option for the request payload, and the promise exposes a .json<T>() method that returns Promise<T>. The README's example posts an object with the json option and reads the parsed result from .json().

Official sources

  1. Issues
  2. License: MIT
  3. README
  4. Releases
  5. sindresorhus/got on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/sindresorhus-got.svg)](https://hysenlabs.com/projects/sindresorhus-got)