The WebSocket Handshake Explained
Dissect the HTTP-based handshake process that upgrades a standard HTTP connection to a WebSocket.
The WebSocket Handshake Explained is a free WebSockets & Realtime Systems Programming lesson on CoddyKit — lesson 1 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the WebSockets & Realtime Systems Programming learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.
Handshake: The Connection Upgrade
Imagine you're calling a friend, but instead of just talking, you first agree on a secret language. The WebSocket handshake is similar!
It's the crucial initial step where your browser (client) and a server agree to switch from a standard HTTP connection to a WebSocket connection.
Beyond HTTP's Limitations
Traditional HTTP is designed for short, one-off requests and responses. Think of loading a webpage – you ask, the server sends, and the connection closes.
- One-way: Client requests, server responds.
- Short-lived: Connection closes after each interaction.
- Overhead: Each new request needs to set up a new connection.
WebSockets need a persistent, two-way street for real-time data.
Client Initiates the Upgrade
The handshake begins with the client (your browser) sending a regular HTTP GET request to the server. But it's not truly "regular"!
This request includes special HTTP headers that signal the client's intention to "upgrade" to the WebSocket protocol. It's like adding a special note to your call asking to switch to the secret language.
Signaling the Intent to Switch
Two key headers clearly tell the server the client wants a WebSocket connection:
Upgrade: websocket: This header specifies the protocol the client wants to switch to.Connection: Upgrade: This header is a general HTTP header that indicates the client wishes to upgrade or switch protocols.
Together, they form the core of the upgrade request.
The Client's Secret Key
Another vital header from the client is Sec-WebSocket-Key.
- It's a 16-byte random value, encoded in Base64.
- It acts as a unique, unpredictable "nonce" (number used once) for each handshake.
- The server uses this key to prove it understands the WebSocket protocol and to prevent certain types of caching or proxy issues.
Protocol Version Check
The Sec-WebSocket-Version header is straightforward but important.
It tells the server which version of the WebSocket protocol the client is using. Currently, the standard version is 13.
This ensures both client and server speak the same "dialect" of the WebSocket language, guaranteeing compatibility.
Server Responds: 101 Switching Protocols
If the server supports WebSockets and agrees to the upgrade, it sends a special HTTP response back to the client.
The most important part of this response is the HTTP status code 101: Switching Protocols. This code explicitly means the server is changing protocols as requested by the client.
Server's Confirmation Key
The server's response also includes key headers:
Upgrade: websocketandConnection: Upgrade: Mirroring the client, these confirm the server's agreement to upgrade.Sec-WebSocket-Accept: This is a hash generated by the server using the client'sSec-WebSocket-Keyplus a specific "magic string". It proves the server understood the key and is capable of WebSockets.
Handshake Key Check
You've learned about the important headers involved in the WebSocket handshake.
Which of the following headers is sent by the client to initiate the WebSocket upgrade, and contains a random, unique value?
Connection Upgraded & Ready!
Once the client receives and validates the server's 101 response with the correct Sec-WebSocket-Accept header, the HTTP handshake is complete!
The connection is now upgraded to a full-duplex WebSocket. Both client and server can send and receive data simultaneously over this persistent connection, enabling true real-time communication.
Frequently asked questions
Is the “The WebSocket Handshake Explained” lesson free?
Yes — the full text of “The WebSocket Handshake Explained” is free to read here on the web, and the WebSockets & Realtime Systems Programming course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the WebSockets & Realtime Systems Programming course, upgrade to CoddyKit PRO.
What will I learn in “The WebSocket Handshake Explained”?
Dissect the HTTP-based handshake process that upgrades a standard HTTP connection to a WebSocket. You practise WebSockets & Realtime Systems Programming with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start WebSockets & Realtime Systems Programming?
No prior experience is required. WebSockets & Realtime Systems Programming on CoddyKit is structured for beginners through advanced learners; this is — lesson 1 of 4, so you can start here or from the beginning and move at your own pace.
How long does the “The WebSocket Handshake Explained” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this WebSockets & Realtime Systems Programming lesson?
Yes. Every WebSockets & Realtime Systems Programming lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- The WebSocket Handshake Explained
- WebSocket Data Framing and Messages
- Connection Lifecycle and States
- Subprotocols, Extensions, and Compression