urllib3 is a pip install away, and its readme is a maintenance pitch
urllib3 is a user-friendly HTTP client library for Python
At a glance
- What is it?
- A user-friendly HTTP client for Python that the readme sells on the features the standard library lacks: thread safety, connection pooling, client-side TLS verification, multipart uploads, retry and redirect helpers, four compression encodings and HTTP plus SOCKS proxy support. Underneath that is a project with a named maintainer list, a paid security channel and a changelog built from news fragments.
- Who is it for?
- urllib3 is the right dependency when you are writing Python that makes more than a handful of HTTP requests, because pooling and thread safety are the two things you will otherwise rebuild badly, and its retry and redirect helpers are already solved. Most of the Python ecosystem is already using it, per the readme's own claim, so the odds are good that it is already in your dependency tree.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 1 day ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 4, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The feature list is what the standard library does not do
The pitch is structured as a gap list. The readme says urllib3 brings many critical features that are missing from the Python standard libraries, and then names them: thread safety, connection pooling, client-side SSL/TLS verification, file uploads with multipart encoding, helpers for retrying requests and dealing with HTTP redirects, support for gzip, deflate, brotli and zstd encoding, and proxy support for both HTTP and SOCKS. Two claims close the list. The last bullet is 100% test coverage, which is a project policy rather than a feature. The paragraph after it is the one to remember when you evaluate a dependency: the maintainers have a 15+ year track record on urllib3 with what the readme calls the highest code standards and attention to security and safety. Then the bluntest line, that much of the Python ecosystem already uses urllib3 and you should too.
python -m pip install urllib3, or clone and install the directory
There are exactly two documented install routes, and the first one is a single command:
$ python -m pip install urllib3The second is from source, and it is three commands rather than one:
$ git clone https://github.com/urllib3/urllib3.git
$ cd urllib3
$ pip install .Note the difference in how they are framed. The pip route names the package; the source route names a GitHub URL and then installs the working directory, so the version you get is whatever the clone contains rather than a published release. That is the route to use if you want the main branch, and it is worth knowing which one you are on because the recent releases, 2.8.0 in September 2026, 2.7.0 in May and 2.6.3 in January, are the numbered ones and the branch is not. The readme also links the PyPI page and the readthedocs documentation rather than repeating either.
The getting-started example is four lines against httpbin
The whole quickstart fits in one interactive block:
>>> import urllib3
>>> resp = urllib3.request("GET", "http://httpbin.org/robots.txt")
>>> resp.status
200
>>> resp.data
b"User-agent: *\nDisallow: /deny\n"Three things are demonstrated in three lines. The entry point is a module-level function, urllib3.request, taking the method and the URL as strings. The response object carries a status as an integer and the body as a bytes attribute rather than as text, so decoding is your decision. And nothing is closed, because there is no session object in this example to manage. That last point is a simplification worth naming: the library's connection pooling is what makes repeated calls cheap, and the quickstart shows the simplest possible call rather than the pooled one, which is left to the reference documentation at urllib3.readthedocs.io.
Duplicate pull requests get rejected without review
The contributing section has an unusually firm paragraph in it. You are asked to read the contributing documentation first, then to check for existing pull requests addressing the same issue and to share feedback in the existing pull request or issue. Then comes the rule: duplicate pull requests, including alternative solutions, will be rejected without review unless a maintainer has approved opening an alternative pull request in advance. So the approval gate is explicit and it comes before the work, not after. That is unusual enough to plan around. If you have a different approach to a problem someone has already opened, the sequence is to ask a maintainer first, and the readme does not describe a faster route for that conversation beyond the community Discord channel.
Security reports go to Tidelift, not to the issue tracker
Vulnerabilities are handled on a separate path from bugs. To report a security vulnerability the readme says to use the Tidelift security contact, and that Tidelift will coordinate the fix and disclosure with the maintainers. There is a repository SECURITY.md and a security page in the documentation for more detail, so the policy exists in two places. The same vendor appears twice more: professional support is sold as part of the Tidelift Subscription, described as a single source for purchasing and maintaining the software with professional grade assurances, and sponsorship for the development itself is a separate page in the documentation. So one commercial relationship covers the incident channel, the support contract and the funding, which is a coherent arrangement and also means the security contact is not a volunteer address.
Eight maintainers are named, and the lead is illia-v
The maintainers section is unusual for a readme and worth reading for that reason. It opens with Meet our maintainers since 2008, then lists eight people with their GitHub handles and full names: a current lead, Illia Volochii as illia-v, then Seth M. Larson, Quentin Pradet, Thea Flowers, Jess Shapiro, Cory Benfield, Ian Stapleton Cordasco and Andrey Petrov, who is also the sole author named in the project metadata with an email address. The ordering is not seniority by any visible measure, but the lead is marked. That gives you two things a dependency rarely tells you: how many people hold the project, and who the manifest says to contact about it. The badges above the same content point at the CI workflow, the docs, deps.dev and the SLSA and OpenSSF best-practice listings, which are the supply-chain signals worth checking before you pin a version.
Free threading is in the classifiers, marked beta
The project metadata is where the compatibility story lives, and pyproject.toml spells it out. The build backend is hatchling with hatch-vcs and setuptools-scm behind it, so the version is dynamic rather than written into the file, and requires-python is >=3.10. The classifier list names every interpreter from 3.10 through 3.15, restricts the package to Python 3 only, and covers both CPython and PyPy. One entry is worth stopping on: Programming Language :: Python :: Free Threading :: 2 - Beta, which says plainly that running without the global interpreter lock is a beta capability rather than a finished one. The optional dependencies follow the same precision, since the brotli extra installs brotli on CPython and brotlicffi everywhere else, chosen by an environment marker on the implementation.
towncrier fragments, a changelog directory and a dummyserver
The tree shows how the release notes are produced. There is a towncrier.toml and a changelog/ directory of news fragments, which together with CHANGES.rst at the root is the towncrier workflow: contributors drop a fragment, the fragments are rendered into the changelog at release time. Automation sits alongside it, with noxfile.py for the test sessions and a ci/ directory for the pipeline, and osv-scanner.toml at the root, which is a dependency vulnerability scanner configured against the project's own lockfile. There is also a setup.cfg next to pyproject.toml, an .eslintrc-style file as eslint.config.cjs in a Python project, and a dummyserver/ directory, which reads as a local HTTP server the test suite points at instead of reaching the internet. Coverage is configured in .coveragerc and the docs in .readthedocs.yml, with uv.lock pinning the development environment.
Editorial conclusion
urllib3 is the right dependency when you are writing Python that makes more than a handful of HTTP requests, because pooling and thread safety are the two things you will otherwise rebuild badly, and its retry and redirect helpers are already solved. Most of the Python ecosystem is already using it, per the readme's own claim, so the odds are good that it is already in your dependency tree. Three things to check. It requires Python 3.10 or above and its classifiers run from 3.10 to 3.15, so anything older is out. Its free-threading support is marked as beta in the classifiers, so do not assume a free-threaded build is a settled thing. And security reports do not go to the issue tracker: the readme routes them to a Tidelift security contact, which then coordinates the fix and disclosure with the maintainers. The library is MIT licensed, and professional support is sold separately through the same vendor.
Frequently asked questions
What is urllib3 used for?
It is an HTTP client library for Python, covering the parts the standard library leaves out: thread safety, connection pooling, client-side SSL/TLS verification, multipart file uploads, retry and redirect helpers, gzip, deflate, brotli and zstd decoding, and HTTP and SOCKS proxy support.
How do I install urllib3?
Run python -m pip install urllib3. Alternatively clone https://github.com/urllib3/urllib3.git, cd urllib3 and run pip install ., which installs the working directory rather than a published version.
Is urllib3 part of the Python standard library?
No, it is a separate library installed from PyPI. Its stated purpose is to bring features that are missing from the Python standard libraries, such as thread safety, connection pooling, retries and redirects.
how to use urllib3
Import the module and call urllib3.request with a method and a URL, then read the result off the response object. The readme's example fetches http://httpbin.org/robots.txt and shows resp.status returning 200 and resp.data returning the body as bytes.
how to import urllib3
The import is plain: import urllib3, with no submodule to reach for. The quickstart then calls urllib3.request("GET", "http://httpbin.org/robots.txt") and reads .status and .data on the response.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/urllib3-urllib3)