Web service ports tell a browser or another client where to connect on a server. Port 80 is normally used for HTTP, while port 443 is normally used for HTTPS. Ports 8080 and 8443 are common alternate ports for HTTP and HTTPS. Development servers, reverse proxies, and hosted applications often use these alternate ports.
The port number and the protocol are related, but they are not the same thing. HTTP defines how a browser sends requests and how a web server returns responses. HTTP is the protocol used to transfer data between a web server and a browser. HTTPS is the secure version of HTTP and encrypts communication between the browser and server. HTTPS protects data exchanged between the browser and the server.
Table of Contents
How the four ports differ
| Port | Typical protocol | Typical role | What users need to know |
|---|---|---|---|
| 80 | HTTP | Standard web traffic | Browsers commonly use this port for an HTTP address without a port suffix. |
| 443 | HTTPS | Standard secure web traffic | Browsers commonly use this port for an HTTPS address without a port suffix. |
| 8080 | HTTP | Alternate web service, development server, or internal application | The port normally has to be included in the address when users connect directly. |
| 8443 | HTTPS | Alternate secure web service, development server, or internal application | The port normally has to be included in the address when users connect directly. |
Port 80 and HTTP
Port 80 is the usual entry point for HTTP traffic. A browser connecting to an HTTP service sends its request using HTTP, and the server returns an HTTP response. The connection is not made secure simply because it uses a web port. HTTP and HTTPS are different protocols, so a service using port 80 must be configured to handle HTTP traffic.
Port 80 is often used as the public HTTP endpoint of a website or reverse proxy. A reverse proxy can receive the request on port 80 and pass it to another web service on an internal port such as 8080. In this arrangement, the browser connects to port 80, while the application may listen on a different port.
Port 443 and HTTPS
Port 443 is the usual entry point for HTTPS traffic. The browser and server communicate using HTTPS, which is the encrypted form of HTTP. The use of port 443 does not replace HTTPS configuration. The service listening on that port must be prepared to accept HTTPS connections.
A reverse proxy can accept HTTPS on port 443 and forward the request to a hosted application on another port. This keeps the public service on the standard secure port while allowing the application to use its own internal listening port.
When port 8080 is appropriate
Port 8080 is commonly used when an HTTP service needs an alternate entry point. Typical examples include a development server, an application running behind a reverse proxy, or a hosted application that does not use the public standard port directly.
Port 8080 uses HTTP, not HTTPS. If a browser connects to http://example.com:8080, it is asking for HTTP on port 8080. If the application on that port expects HTTPS instead, the connection can fail because the browser and service are using different protocols.
When port 8443 is appropriate
Port 8443 is commonly used as an alternate HTTPS port. It is useful when a secure application must listen separately from the service using port 443, such as an internal application, development server, or hosted service behind a reverse proxy.
Port 8443 uses HTTPS only when the service listening there is configured for HTTPS. The number 8443 does not provide encryption by itself. The application must speak HTTPS and return HTTPS responses.
How port mappings affect browsers and proxies
A browser sends traffic to the host and port named in the address. Standard HTTP and HTTPS addresses normally use ports 80 and 443, so those port numbers are often omitted. An alternate port must be identified explicitly, for example http://example.com:8080 or https://example.com:8443.
A reverse proxy must map the public port to a service that uses the expected protocol. Common arrangements include:
- Port 80 receiving HTTP and forwarding to an HTTP application on port 8080.
- Port 443 receiving HTTPS and forwarding to an application on port 8080.
- Port 443 receiving HTTPS and forwarding to an HTTPS application on port 8443.
The exact mapping depends on whether the application behind the proxy expects HTTP or HTTPS. The proxy and the application must use matching settings for the connection between them.
Common errors caused by incorrect port or protocol mapping
- HTTP sent to an HTTPS port: The browser connects to a service expecting encrypted HTTPS data, but sends a plain HTTP request. The service may reject the request or close the connection.
- HTTPS sent to an HTTP port: The browser begins an HTTPS connection, but the service returns a plain HTTP response. The browser may show a secure connection or protocol error.
- Wrong alternate port in the address: The browser reaches a different service, or no service is listening on that port. The result can be a failed connection or an unexpected response.
- Blocked port: A firewall or proxy may prevent access to the port even when the application is running. The public port, firewall rule, and proxy mapping must allow the same connection path.
Choosing the right port
Use port 80 for a standard HTTP endpoint and port 443 for a standard HTTPS endpoint. Use 8080 when an alternate HTTP listener is needed, and use 8443 when an alternate HTTPS listener is needed. For every deployment, confirm three settings together: the protocol expected by the service, the port where it listens, and the port exposed by the firewall or reverse proxy.