<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Constrained Application Protocol</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Constrained_Application_Protocol"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/ext.pygments.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Constrained_Application_Protocol rootpage-Constrained_Application_Protocol skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Constrained Application Protocol</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1129693374">
/* start https://en.wikipedia.org/ */
.mw-parser-output .hlist dl,.mw-parser-output .hlist ol,.mw-parser-output .hlist ul{margin:0;padding:0}.mw-parser-output .hlist dd,.mw-parser-output .hlist dt,.mw-parser-output .hlist li{margin:0;display:inline}.mw-parser-output .hlist.inline,.mw-parser-output .hlist.inline dl,.mw-parser-output .hlist.inline ol,.mw-parser-output .hlist.inline ul,.mw-parser-output .hlist dl dl,.mw-parser-output .hlist dl ol,.mw-parser-output .hlist dl ul,.mw-parser-output .hlist ol dl,.mw-parser-output .hlist ol ol,.mw-parser-output .hlist ol ul,.mw-parser-output .hlist ul dl,.mw-parser-output .hlist ul ol,.mw-parser-output .hlist ul ul{display:inline}.mw-parser-output .hlist .mw-empty-li{display:none}.mw-parser-output .hlist dt::after{content:": "}.mw-parser-output .hlist dd::after,.mw-parser-output .hlist li::after{content:" · ";font-weight:bold}.mw-parser-output .hlist dd:last-child::after,.mw-parser-output .hlist dt:last-child::after,.mw-parser-output .hlist li:last-child::after{content:none}.mw-parser-output .hlist dd dd:first-child::before,.mw-parser-output .hlist dd dt:first-child::before,.mw-parser-output .hlist dd li:first-child::before,.mw-parser-output .hlist dt dd:first-child::before,.mw-parser-output .hlist dt dt:first-child::before,.mw-parser-output .hlist dt li:first-child::before,.mw-parser-output .hlist li dd:first-child::before,.mw-parser-output .hlist li dt:first-child::before,.mw-parser-output .hlist li li:first-child::before{content:" (";font-weight:normal}.mw-parser-output .hlist dd dd:last-child::after,.mw-parser-output .hlist dd dt:last-child::after,.mw-parser-output .hlist dd li:last-child::after,.mw-parser-output .hlist dt dd:last-child::after,.mw-parser-output .hlist dt dt:last-child::after,.mw-parser-output .hlist dt li:last-child::after,.mw-parser-output .hlist li dd:last-child::after,.mw-parser-output .hlist li dt:last-child::after,.mw-parser-output .hlist li li:last-child::after{content:")";font-weight:normal}.mw-parser-output .hlist ol{counter-reset:listitem}.mw-parser-output .hlist ol>li{counter-increment:listitem}.mw-parser-output .hlist ol>li::before{content:" "counter(listitem)"\a0 "}.mw-parser-output .hlist dd ol>li:first-child::before,.mw-parser-output .hlist dt ol>li:first-child::before,.mw-parser-output .hlist li ol>li:first-child::before{content:" ("counter(listitem)"\a0 "}
/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1246091330">
/* start https://en.wikipedia.org/ */
.mw-parser-output .sidebar{width:22em;float:right;clear:right;margin:0.5em 0 1em 1em;background:var(--background-color-neutral-subtle,#f8f9fa);border:1px solid var(--border-color-base,#a2a9b1);padding:0.2em;text-align:center;line-height:1.4em;font-size:88%;border-collapse:collapse;display:table}body.skin-minerva .mw-parser-output .sidebar{display:table!important;float:right!important;margin:0.5em 0 1em 1em!important}.mw-parser-output .sidebar-subgroup{width:100%;margin:0;border-spacing:0}.mw-parser-output .sidebar-left{float:left;clear:left;margin:0.5em 1em 1em 0}.mw-parser-output .sidebar-none{float:none;clear:both;margin:0.5em 1em 1em 0}.mw-parser-output .sidebar-outer-title{padding:0 0.4em 0.2em;font-size:125%;line-height:1.2em;font-weight:bold}.mw-parser-output .sidebar-top-image{padding:0.4em}.mw-parser-output .sidebar-top-caption,.mw-parser-output .sidebar-pretitle-with-top-image,.mw-parser-output .sidebar-caption{padding:0.2em 0.4em 0;line-height:1.2em}.mw-parser-output .sidebar-pretitle{padding:0.4em 0.4em 0;line-height:1.2em}.mw-parser-output .sidebar-title,.mw-parser-output .sidebar-title-with-pretitle{padding:0.2em 0.8em;font-size:145%;line-height:1.2em}.mw-parser-output .sidebar-title-with-pretitle{padding:0.1em 0.4em}.mw-parser-output .sidebar-image{padding:0.2em 0.4em 0.4em}.mw-parser-output .sidebar-heading{padding:0.1em 0.4em}.mw-parser-output .sidebar-content{padding:0 0.5em 0.4em}.mw-parser-output .sidebar-content-with-subgroup{padding:0.1em 0.4em 0.2em}.mw-parser-output .sidebar-above,.mw-parser-output .sidebar-below{padding:0.3em 0.8em;font-weight:bold}.mw-parser-output .sidebar-collapse .sidebar-above,.mw-parser-output .sidebar-collapse .sidebar-below{border-top:1px solid #aaa;border-bottom:1px solid #aaa}.mw-parser-output .sidebar-navbar{text-align:right;font-size:115%;padding:0 0.4em 0.4em}.mw-parser-output .sidebar-list-title{padding:0 0.4em;text-align:left;font-weight:bold;line-height:1.6em;font-size:105%}.mw-parser-output .sidebar-list-title-c{padding:0 0.4em;text-align:center;margin:0 3.3em}@media(max-width:640px){body.mediawiki .mw-parser-output .sidebar{width:100%!important;clear:both;float:none!important;margin-left:0!important;margin-right:0!important}}body.skin--responsive .mw-parser-output .sidebar a>img{max-width:none!important}@media screen{html.skin-theme-clientpref-night .mw-parser-output .sidebar:not(.notheme) .sidebar-list-title,html.skin-theme-clientpref-night .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle{background:transparent!important}html.skin-theme-clientpref-night .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle a{color:var(--color-progressive)!important}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .sidebar:not(.notheme) .sidebar-list-title,html.skin-theme-clientpref-os .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle{background:transparent!important}html.skin-theme-clientpref-os .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle a{color:var(--color-progressive)!important}}@media print{body.ns-0 .mw-parser-output .sidebar{display:none!important}}
/* end https://en.wikipedia.org/ */
</style><table class="sidebar nomobile nowraplinks hlist"><tbody><tr><th class="sidebar-title"><a href="Internet_protocol_suite" title="Internet protocol suite">Internet protocol suite</a></th></tr><tr><th class="sidebar-heading">
<a href="Application_layer" title="Application layer">Application layer</a></th></tr><tr><td class="sidebar-content">
<ul><li><a href="Border_Gateway_Protocol" title="Border Gateway Protocol">BGP</a></li>
<li><a href="Dynamic_Host_Configuration_Protocol" title="Dynamic Host Configuration Protocol">DHCP</a> (<a href="DHCPv6" title="DHCPv6">v6</a>)</li>
<li><a href="Domain_Name_System" title="Domain Name System">DNS</a></li>
<li><a href="File_Transfer_Protocol" title="File Transfer Protocol">FTP</a></li>
<li><a href="HTTP" title="HTTP">HTTP</a> (<a href="HTTP/3" title="HTTP/3">HTTP/3</a>)</li>
<li><a href="HTTPS" title="HTTPS">HTTPS</a></li>
<li><a href="Internet_Message_Access_Protocol" title="Internet Message Access Protocol">IMAP</a></li>
<li><a href="Internet_Printing_Protocol" title="Internet Printing Protocol">IPP</a></li>
<li><a href="IRC" title="IRC">IRC</a></li>
<li><a href="Lightweight_Directory_Access_Protocol" title="Lightweight Directory Access Protocol">LDAP</a></li>
<li><a href="Media_Gateway_Control_Protocol" title="Media Gateway Control Protocol">MGCP</a></li>
<li><a href="MQTT" title="MQTT">MQTT</a></li>
<li><a href="Network_News_Transfer_Protocol" title="Network News Transfer Protocol">NNTP</a></li>
<li><a href="Network_Time_Protocol" title="Network Time Protocol">NTP</a></li>
<li><a href="Open_Shortest_Path_First" title="Open Shortest Path First">OSPF</a></li>
<li><a href="Post_Office_Protocol" title="Post Office Protocol">POP</a></li>
<li><a href="Precision_Time_Protocol" title="Precision Time Protocol">PTP</a></li>
<li><a href="Open_Network_Computing_Remote_Procedure_Call" class="mw-redirect" title="Open Network Computing Remote Procedure Call">ONC/RPC</a></li>
<li><a href="Real-time_Transport_Protocol" title="Real-time Transport Protocol">RTP</a></li>
<li><a href="Real-Time_Streaming_Protocol" title="Real-Time Streaming Protocol">RTSP</a></li>
<li><a href="Routing_Information_Protocol" title="Routing Information Protocol">RIP</a></li>
<li><a href="Session_Initiation_Protocol" title="Session Initiation Protocol">SIP</a></li>
<li><a href="Simple_Mail_Transfer_Protocol" title="Simple Mail Transfer Protocol">SMTP</a></li>
<li><a href="Simple_Network_Management_Protocol" title="Simple Network Management Protocol">SNMP</a></li>
<li><a href="Secure_Shell" title="Secure Shell">SSH</a></li>
<li><a href="Telnet" title="Telnet">Telnet</a></li>
<li><a href="Transport_Layer_Security" title="Transport Layer Security">TLS/SSL</a></li>
<li><a href="XMPP" title="XMPP">XMPP</a></li>
<li><i>more...</i></li></ul></td>
</tr><tr><th class="sidebar-heading">
<a href="Transport_layer" title="Transport layer">Transport layer</a></th></tr><tr><td class="sidebar-content">
<ul><li><a href="Transmission_Control_Protocol" title="Transmission Control Protocol">TCP</a></li>
<li><a href="User_Datagram_Protocol" title="User Datagram Protocol">UDP</a></li>
<li><a href="Datagram_Congestion_Control_Protocol" title="Datagram Congestion Control Protocol">DCCP</a></li>
<li><a href="Stream_Control_Transmission_Protocol" title="Stream Control Transmission Protocol">SCTP</a></li>
<li><a href="Resource_Reservation_Protocol" title="Resource Reservation Protocol">RSVP</a></li>
<li><a href="QUIC" title="QUIC">QUIC</a></li>
<li><i>more...</i></li></ul></td>
</tr><tr><th class="sidebar-heading">
<a href="Internet_layer" title="Internet layer">Internet layer</a></th></tr><tr><td class="sidebar-content">
<ul><li><a href="Internet_Protocol" title="Internet Protocol">IP</a>
<ul><li><a href="IPv4" title="IPv4">v4</a></li>
<li><a href="IPv6" title="IPv6">v6</a></li></ul></li>
<li><a href="Internet_Control_Message_Protocol" title="Internet Control Message Protocol">ICMP</a> (<a href="ICMPv6" title="ICMPv6">v6</a>)</li>
<li><a href="Neighbor_Discovery_Protocol" title="Neighbor Discovery Protocol">NDP</a></li>
<li><a href="Explicit_Congestion_Notification" title="Explicit Congestion Notification">ECN</a></li>
<li><a href="Internet_Group_Management_Protocol" title="Internet Group Management Protocol">IGMP</a></li>
<li><a href="IPsec" title="IPsec">IPsec</a></li>
<li><i>more...</i></li></ul></td>
</tr><tr><th class="sidebar-heading">
<a href="Link_layer" title="Link layer">Link layer</a></th></tr><tr><td class="sidebar-content">
<ul><li><a href="Address_Resolution_Protocol" title="Address Resolution Protocol">ARP</a></li>
<li><a href="Tunneling_protocol" title="Tunneling protocol">Tunnels</a></li>
<li><a href="Point-to-Point_Protocol" title="Point-to-Point Protocol">PPP</a></li>
<li><a href="Medium_access_control" title="Medium access control">MAC</a></li>
<li><i>more...</i></li></ul></td>
</tr><tr><td class="sidebar-navbar"><style data-mw-deduplicate="TemplateStyles:r1239400231">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbar{display:inline;font-size:88%;font-weight:normal}.mw-parser-output .navbar-collapse{float:left;text-align:left}.mw-parser-output .navbar-boxtext{word-spacing:0}.mw-parser-output .navbar ul{display:inline-block;white-space:nowrap;line-height:inherit}.mw-parser-output .navbar-brackets::before{margin-right:-0.125em;content:"[ "}.mw-parser-output .navbar-brackets::after{margin-left:-0.125em;content:" ]"}.mw-parser-output .navbar li{word-spacing:-0.125em}.mw-parser-output .navbar a>span,.mw-parser-output .navbar a>abbr{text-decoration:inherit}.mw-parser-output .navbar-mini abbr{font-variant:small-caps;border-bottom:none;text-decoration:none;cursor:inherit}.mw-parser-output .navbar-ct-full{font-size:114%;margin:0 7em}.mw-parser-output .navbar-ct-mini{font-size:114%;margin:0 4em}html.skin-theme-clientpref-night .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}@media(prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}}@media print{.mw-parser-output .navbar{display:none!important}}
/* end https://en.wikipedia.org/ */
</style></td></tr></tbody></table>
<p><b>Constrained Application Protocol</b> (<b>CoAP</b>) is a specialized <a href="User_Datagram_Protocol" title="User Datagram Protocol">UDP-based</a> Internet application protocol for constrained devices, as defined in <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc7252">RFC 7252</a> (published in 2014). It enables those constrained devices called "nodes" to communicate with the wider Internet using similar protocols.
CoAP is designed for use between devices on the same constrained network (e.g., low-power, lossy networks), between devices and general nodes on the Internet, and between devices on different constrained networks both joined by an internet. CoAP is also being used via other mechanisms, such as SMS on mobile communication networks.
</p><p>CoAP is an application-layer protocol that is intended for use in resource-constrained Internet devices, such as <a href="Wireless_sensor_network" title="Wireless sensor network">wireless sensor network</a> nodes. CoAP is designed to easily translate to <a href="HTTP" title="HTTP">HTTP</a> for simplified integration with the web, while also meeting specialized requirements such as <a href="Multicast" title="Multicast">multicast</a> support, very low overhead, and simplicity.<sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> Multicast, low overhead, and simplicity are important for <a href="Internet_of_things" title="Internet of things">Internet of things</a> (IoT) and <a href="Machine-to-machine" class="mw-redirect" title="Machine-to-machine">machine-to-machine</a> (M2M) communication, which tend to be <a href="Embedded_system" title="Embedded system">embedded</a> and have much less memory and power supply than traditional Internet devices have. Therefore, efficiency is very important. CoAP can run on most devices that support UDP or a UDP analogue.
</p><p>The Internet Engineering Task Force (<a href="IETF" class="mw-redirect" title="IETF">IETF</a>) Constrained <a href="RESTful" class="mw-redirect" title="RESTful">RESTful</a> Environments Working Group (<a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/charter-ietf-core/">CoRE</a>) has done the major standardization work for this protocol. In order to make the protocol suitable to IoT and M2M applications, various new functions have been added.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Specification">Specification</h2></div>
<p>The core of the protocol is specified in <style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a> <a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc7252">7252</a>. Various extensions have been proposed, particularly:
</p>
<ul><li><a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a> <a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc7641">7641</a> (2015) Observing Resources in the Constrained Application Protocol</li>
<li><a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a> <a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc7959">7959</a> (2016) Block-Wise Transfers in the Constrained Application Protocol (CoAP)</li>
<li><a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a> <a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc8323">8323</a> (2018) CoAP (Constrained Application Protocol) over TCP, TLS, and <a href="WebSocket" title="WebSocket">WebSockets</a></li>
<li><a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a> <a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc8974">8974</a> (2021) Extended Tokens and Stateless Clients in the Constrained Application Protocol (CoAP)</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Message_formats">Message formats</h2></div>
<p>CoAP makes use of two message types, requests and responses, using a simple, binary header format. CoAP is by default bound to <a href="User_Datagram_Protocol" title="User Datagram Protocol">UDP</a> and optionally to <a href="DTLS" class="mw-redirect" title="DTLS">DTLS</a>, providing a high level of communications security. When bound to UDP, the entire message <i>must</i> fit within a single datagram. When used with <a href="6LoWPAN" title="6LoWPAN">6LoWPAN</a> as defined in RFC 4944, messages <i>should</i> fit into a single <a href="IEEE_802.15.4" title="IEEE 802.15.4">IEEE 802.15.4</a> frame to minimize fragmentation.
</p><p>The smallest CoAP message is 4 bytes in length, if the token, options and payload fields are omitted, i.e. if it only consists of the CoAP header. The header is followed by the token value (0 to 8 bytes) which may be followed by a list of options in an optimized type–length–value format. Any bytes after the header, token and options (if any) are considered the message payload, which is prefixed by the one-byte "payload marker" (0xFF). The length of the payload is implied by the datagram length.
</p>
<table class="wikitable" style="margin: 0 auto; text-align:center">
<caption>CoAP Message
</caption>
<tbody><tr>
<th><a href="Octet_(computing)" title="Octet (computing)">Octet</a> offset</th>
<th></th>
<th colspan="8">0</th>
<th colspan="8">1</th>
<th colspan="8">2</th>
<th colspan="8">3
</th></tr>
<tr>
<th></th>
<th><a href="Bit_(computing)" class="mw-redirect" title="Bit (computing)">Bit</a> offset</th>
<th>0</th>
<th>1</th>
<th>2</th>
<th>3</th>
<th>4</th>
<th>5</th>
<th>6</th>
<th>7</th>
<th>8</th>
<th>9</th>
<th>10</th>
<th>11</th>
<th>12</th>
<th>13</th>
<th>14</th>
<th>15</th>
<th>16</th>
<th>17</th>
<th>18</th>
<th>19</th>
<th>20</th>
<th>21</th>
<th>22</th>
<th>23</th>
<th>24</th>
<th>25</th>
<th>26</th>
<th>27</th>
<th>28</th>
<th>29</th>
<th>30</th>
<th>31
</th></tr>
<tr>
<th>4</th>
<th>32
</th>
<td colspan="2">ver</td>
<td colspan="2">type</td>
<td colspan="4">token length</td>
<td colspan="8">request/response code</td>
<td colspan="16">message ID
</td></tr>
<tr>
<th>8</th>
<th>64
</th>
<td colspan="32" rowspan="2">token (0–8 bytes)
</td></tr>
<tr>
<th>12</th>
<th>96
</th></tr>
<tr>
<th>16</th>
<th>128
</th>
<td colspan="32">options (if available)
</td></tr>
<tr>
<th>20</th>
<th>160
</th>
<td>1</td>
<td>1</td>
<td>1</td>
<td>1</td>
<td>1</td>
<td>1</td>
<td>1</td>
<td>1</td>
<td colspan="24">payload (if available)
</td></tr></tbody></table>
<div class="mw-heading mw-heading3"><h3 id="CoAP_fixed-size_header">CoAP fixed-size header</h3></div>
<p>The first 4 bytes are mandatory in all CoAP datagrams, they constitute the fixed-size header.
</p><p>These fields can be extracted from these 4 bytes in C via these macros:
</p>
<div class="mw-highlight mw-highlight-lang-c mw-content-ltr" dir="ltr"><pre><span class="cp">#define COAP_HEADER_VERSION(data) ( (0xC0 & (data)[0]) >> 6 )</span>
<span class="cp">#define COAP_HEADER_TYPE(data) ( (0x30 & (data)[0]) >> 4 )</span>
<span class="cp">#define COAP_HEADER_TKL(data) ( (0x0F & (data)[0]) >> 0 )</span>
<span class="cp">#define COAP_HEADER_CLASS(data) ( ((data)[1] >> 5) & 0x07 )</span>
<span class="cp">#define COAP_HEADER_CODE(data) ( ((data)[1] >> 0) & 0x1F )</span>
<span class="cp">#define COAP_HEADER_MID(data) ( ((data)[2] << 8) | (data)[3] )</span>
</pre></div>
<div class="mw-heading mw-heading4"><h4 id="Version_(ver)_(2_bits)">Version (ver) (2 bits)</h4></div>
<dl><dd>Indicates the CoAP version number.</dd></dl>
<div class="mw-heading mw-heading4"><h4 id="Type_(2_bits)">Type (2 bits)</h4></div>
<dl><dd>This describes the datagram's message type for the two message type context of Request and Response.
<ul><li>Request
<ul><li>0 : Confirmable : This message expects a corresponding acknowledgement message.</li>
<li>1 : Non-confirmable : This message does not expect a confirmation message.</li></ul></li>
<li>Response
<ul><li>2 : Acknowledgement : This message is a response that acknowledge a confirmable message</li>
<li>3 : Reset : This message indicates that it had received a message but could not process it.</li></ul></li></ul></dd></dl>
<div class="mw-heading mw-heading4"><h4 id="Token_length_(4_bits)">Token length (4 bits)</h4></div>
<dl><dd>Indicates the length of the variable-length Token field, which may be 0–8 bytes in length.</dd></dl>
<div class="mw-heading mw-heading4"><h4 id="Request/response_code_(8_bits)">Request/response code (8 bits)</h4></div>
<table class="wikitable">
<tbody><tr>
<th>0
</th>
<th>1
</th>
<th>2
</th>
<th>3
</th>
<th>4
</th>
<th>5
</th>
<th>6
</th>
<th>7
</th></tr>
<tr>
<td colspan="3">Class
</td>
<td colspan="5">Code
</td></tr></tbody></table>
<p>The three most significant bits form a number known as the "class", which is analogous to the <a href="List_of_HTTP_status_codes" title="List of HTTP status codes">class of HTTP status codes</a>. The five least significant bits form a code that communicates further detail about the request or response. The entire code is typically communicated in the form <code>class.code</code> .
</p><p>You can find the latest CoAP request/response codes at <a rel="nofollow" class="external autonumber" href="https://www.iana.org/assignments/core-parameters/core-parameters.xhtml#codes">[1]</a>, though the below list gives some examples:
</p>
<style data-mw-deduplicate="TemplateStyles:r1184024115">
/* start https://en.wikipedia.org/ */
.mw-parser-output .div-col{margin-top:0.3em;column-width:30em}.mw-parser-output .div-col-small{font-size:90%}.mw-parser-output .div-col-rules{column-rule:1px solid #aaa}.mw-parser-output .div-col dl,.mw-parser-output .div-col ol,.mw-parser-output .div-col ul{margin-top:0}.mw-parser-output .div-col li,.mw-parser-output .div-col dd{page-break-inside:avoid;break-inside:avoid-column}
/* end https://en.wikipedia.org/ */
</style><div class="div-col" style="column-width: 22em;">
<ul><li>Method: 0.XX <div><ol start="0"><li>EMPTY</li><li>GET</li><li>POST</li><li>PUT</li><li>DELETE</li><li>FETCH</li><li>PATCH</li><li>iPATCH</li></ol></div></li>
<li>Success: 2.XX <div><ol><li>Created</li><li>Deleted</li><li>Valid</li><li>Changed</li><li>Content</li><li value="31">Continue</li></ol></div></li>
<li>Client Error: 4.XX <div><ol start="0"><li>Bad Request</li><li>Unauthorized</li><li>Bad Option</li><li>Forbidden</li><li>Not Found</li><li>Method Not Allowed</li><li>Not Acceptable</li><li value="8">Request Entity Incomplete</li><li>Conflict</li><li value="12">Precondition Failed</li><li>Request Entity Too Large</li><li value="15">Unsupported Content-Format</li></ol></div></li>
<li>Server error: 5.XX <div><ol start="0"><li>Internal server error</li><li>Not implemented</li><li>Bad gateway</li><li>Service unavailable</li><li>Gateway timeout</li><li>Proxying not supported</li></ol></div></li>
<li>Signaling Codes: 7.XX <div><ol start="0"><li>Unassigned</li><li>CSM</li><li>Ping</li><li>Pong</li><li>Release</li><li>Abort</li></ol></div></li></ul>
</div>
<div class="mw-heading mw-heading4"><h4 id="Message_ID_(16_bits)">Message ID (16 bits)</h4></div>
<dl><dd>Used to detect message duplication and to match messages of type acknowledgement/reset to messages of type confirmable/non-confirmable.</dd></dl>
<div class="mw-heading mw-heading3"><h3 id="Token">Token</h3></div>
<p>Every request carries a token (but it may be zero length) whose value was generated by the client. The server must echo every token value without any modification back to the client in the corresponding response. It is intended for use as a client-local identifier to match requests and responses, especially for concurrent requests.
</p><p>Matching requests and responses is not done with the message ID because a response may be sent in a different message than the acknowledgement (which uses the message ID for matching). For example, this could be done to prevent retransmissions if obtaining the result takes some time. Such a detached response is called "separate response". In contrast, transmitting the response directly in the acknowledgement is called "piggybacked response" which is expected to be preferred for efficiency reasons.
</p>
<div class="mw-heading mw-heading3"><h3 id="Option">Option</h3></div>
<table class="wikitable">
<caption>Option Format
</caption>
<tbody><tr>
<th colspan="8">Bit position
</th></tr>
<tr>
<th>0
</th>
<th>1
</th>
<th>2
</th>
<th>3
</th>
<th>4
</th>
<th>5
</th>
<th>6
</th>
<th>7
</th></tr>
<tr>
<td colspan="4">Option delta
</td>
<td colspan="4">Option length
</td></tr>
<tr>
<td colspan="8">Option delta extended (none, 8 bits, 16 bits)
</td></tr>
<tr>
<td colspan="8">Option length extended (none, 8 bits, 16 bits)
</td></tr>
<tr>
<td colspan="8">Option value
</td></tr></tbody></table>
<p>Option delta:
</p>
<ul><li>0 to 12: For delta between 0 and 12: Represents the exact delta value between the last option ID and the desired option ID, with no option delta extended value</li>
<li>13: For delta from 13 to 268: Option delta extended is an 8-bit value that represents the option delta value minus 13</li>
<li>14: For delta from 269 to 65,804: Option delta extended is a 16-bit value that represents the option delta value minus 269</li>
<li>15: Reserved for payload marker, where the option delta and option length are set together as 0xFF.</li></ul>
<p>Option length:
</p>
<ul><li>0 to 12: For option length between 0 and 12: Represents the exact length value, with no option length extended value</li>
<li>13: For option length from 13 to 268: Option length extended is an 8-bit value that represents the option length value minus 13</li>
<li>14: For option length from 269 to 65,804: Option length extended is a 16-bit value that represents the option length value minus 269</li>
<li>15: Reserved for future use. It is an error for the option length field to be set to 0xFF.</li></ul>
<p>Option value:
</p>
<ul><li>Size of option value field is defined by option length value in bytes.</li>
<li>Semantic and format this field depends on the respective option.</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Active_protocol_implementations">Active protocol implementations</h2></div>
<table class="wikitable sortable">
<tbody><tr>
<th>Name</th>
<th>Programming Language</th>
<th>Implemented CoAP version</th>
<th>Client/Server</th>
<th>Implemented CoAP features</th>
<th>License</th>
<th>Link
</th></tr>
<tr>
<td>coap</td>
<td>Dart</td>
<td>RFC 7252</td>
<td>Client</td>
<td>Blockwise Transfers, Observe, Multicast, Proxying (partial)</td>
<td>MIT</td>
<td><a rel="nofollow" class="external free" href="https://github.com/shamblett/coap">https://github.com/shamblett/coap</a>
</td></tr>
<tr>
<td>aiocoap</td>
<td>Python 3</td>
<td>RFC 7252, RFC 7641, RFC 7959, RFC 8323, RFC 7967, RFC 8132, RFC 9176, RFC 8613, RFC 9528</td>
<td>Client + Server</td>
<td>Blockwise Transfers, Observe (partial)</td>
<td>MIT</td>
<td><span class="url"><a rel="nofollow" class="external text" href="https://pypi.python.org/pypi/aiocoap">pypi<wbr>.python<wbr>.org<wbr>/pypi<wbr>/aiocoap</a></span>
</td></tr>
<tr>
<td>Californium</td>
<td>Java</td>
<td>RFC 7252, RFC 7641, RFC 7959</td>
<td>Client + Server</td>
<td>Observe, Blockwise Transfers, Multicast (since 2.x), DTLS (+ DTLS 1.2 Connection ID)</td>
<td>EPL+EDL</td>
<td><span class="url"><a rel="nofollow" class="external text" href="https://www.eclipse.org/californium">www<wbr>.eclipse<wbr>.org<wbr>/californium</a></span> <span class="url"><a rel="nofollow" class="external text" href="https://github.com/eclipse/californium">github<wbr>.com<wbr>/eclipse<wbr>/californium</a></span>
</td></tr>
<tr>
<td>CoAPSharp</td>
<td>C#, .NET</td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td>Core, Observe, Block, RD</td>
<td>MIT</td>
<td><span class="url"><a rel="nofollow" class="external text" href="http://www.coapsharp.com%20https://github.com/FemtomaxInc/coapsharp">http://www.coapsharp.com%20https://github.com/FemtomaxInc/coapsharp</a></span>
</td></tr>
<tr>
<td>FreeCoAP</td>
<td>C</td>
<td>RFC 7252</td>
<td>Client + Server + HTTP/CoAP Proxy</td>
<td>Core, DTLS, Blockwise Transfers</td>
<td>BSD</td>
<td><span class="url"><a rel="nofollow" class="external text" href="https://github.com/keith-cullen/FreeCoAP">github<wbr>.com<wbr>/keith-cullen<wbr>/FreeCoAP</a></span>
</td></tr>
<tr>
<td>Go-CoAP</td>
<td><a href="Go_(programming_language)" title="Go (programming language)">Go</a></td>
<td>RFC 7252, RFC 8232, RFC 7641, RFC 7959</td>
<td>Client + Server</td>
<td>Core, Observe, Blockwise, Multicast, TCP/TLS</td>
<td>Apache License 2.0</td>
<td><span class="url"><a rel="nofollow" class="external text" href="https://github.com/plgd-dev/go-coap">github<wbr>.com<wbr>/plgd-dev<wbr>/go-coap</a></span>
</td></tr>
<tr>
<td>java-coap</td>
<td>Java</td>
<td>RFC 7252, RFC 7641, RFC 7959, RFC 8323</td>
<td>Client + Server</td>
<td></td>
<td>Apache License 2.0</td>
<td><span class="url"><a rel="nofollow" class="external text" href="https://github.com/PelionIoT/java-coap">github<wbr>.com<wbr>/PelionIoT<wbr>/java-coap</a></span>
</td></tr>
<tr>
<td>libcoap</td>
<td>C</td>
<td>RFC 7252, RFC 7390, RFC 7641, RFC 7959, RFC 7967, RFC 8132, RFC 8323, RFC 8516, RFC 8613, RFC 8768, RFC 8974, RFC 9175, RFC 9177</td>
<td>Client + Server</td>
<td>Core, Observe, Multicast, Blockwise Transfers, Patch/Fetch, OSCORE, (D)TLS</td>
<td>BSD/GPL</td>
<td><a rel="nofollow" class="external free" href="https://github.com/obgm/libcoap">https://github.com/obgm/libcoap</a>
</td></tr>
<tr>
<td>libcoapy
</td>
<td>Python
</td>
<td colspan="3">same support as libcoap
</td>
<td>MIT
</td>
<td><span class="url"><a rel="nofollow" class="external text" href="https://github.com/anyc/libcoapy">github<wbr>.com<wbr>/anyc<wbr>/libcoapy</a></span>
</td></tr>
<tr>
<td>lobaro-coap</td>
<td>C</td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td>Observe, Blockwise Transfers</td>
<td>MIT</td>
<td><span class="url"><a rel="nofollow" class="external text" href="http://www.lobaro.com/lobaro-coap">www<wbr>.lobaro<wbr>.com<wbr>/lobaro-coap</a></span>
</td></tr>
<tr>
<td>microCoAPy</td>
<td>MicroPython</td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td>Core</td>
<td>Apache License 2.0</td>
<td><span class="url"><a rel="nofollow" class="external text" href="https://github.com/insighio/microCoAPy">github<wbr>.com<wbr>/insighio<wbr>/microCoAPy</a></span>
</td></tr>
<tr>
<td>nanoCoAP</td>
<td>C</td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td>Core, Blockwise Transfers, DTLS</td>
<td>LGPL</td>
<td><span class="url"><a rel="nofollow" class="external text" href="https://api.riot-os.org/group__net__nanocoap.html">api<wbr>.riot-os<wbr>.org<wbr>/group<wbr>__net<wbr>__nanocoap<wbr>.html</a></span>
</td></tr>
<tr>
<td>node-coap</td>
<td>JavaScript</td>
<td>RFC 7252,
<p>RFC 7641, RFC 7959
</p>
</td>
<td>Client + Server</td>
<td>Core, Observe, Block</td>
<td>MIT</td>
<td><span class="url"><a rel="nofollow" class="external text" href="https://github.com/mcollina/node-coap">github<wbr>.com<wbr>/mcollina<wbr>/node-coap</a></span>
</td></tr>
<tr>
<td>Qt CoAP</td>
<td>C++</td>
<td>RFC 7252</td>
<td>Client</td>
<td>Core, Observe, Blockwise Transfers</td>
<td>GPL, Commercial</td>
<td><a rel="nofollow" class="external free" href="https://doc.qt.io/qt-6/qtcoap-index.html">https://doc.qt.io/qt-6/qtcoap-index.html</a>
</td></tr>
<tr>
<td>coap-rs</td>
<td>Rust</td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td>Core, Multicast, Observe option, <i>Too Many Requests</i> Response Code</td>
<td>MIT</td>
<td><span class="url"><a rel="nofollow" class="external text" href="https://github.com/Covertness/coap-rs">github<wbr>.com<wbr>/Covertness<wbr>/coap-rs</a></span>
<p><span class="url"><a rel="nofollow" class="external text" href="https://docs.rs/coap/">docs<wbr>.rs<wbr>/coap<wbr>/</a></span>
</p>
</td></tr>
</tbody></table>
<div class="mw-heading mw-heading2"><h2 id="Proxy_implementations">Proxy implementations</h2></div>
<p>There exist <a href="Proxy_server" title="Proxy server">proxy</a> implementations which provide <a href="Forward_proxy" class="mw-redirect" title="Forward proxy">forward</a> or <a href="Reverse_proxy" title="Reverse proxy">reverse</a> proxy functionality for the CoAP protocol and also implementations which translate between protocols like HTTP and CoAP.
</p><p>The following projects provide proxy functionality:
</p>
<ul><li><a rel="nofollow" class="external text" href="http://telecom.dei.unipd.it/pages/read/90/">Squid 3.1.9 with transparent HTTP-CoAP mapping module</a></li>
<li><a rel="nofollow" class="external text" href="https://code.google.com/p/jcoap/">jcoap Proxy</a></li>
<li><a rel="nofollow" class="external text" href="https://github.com/eclipse/californium/tree/master/californium-proxy2">Californium cf-proxy2</a></li>
<li><a rel="nofollow" class="external text" href="https://github.com/Tanganelli/CoAPthon">CoAPthon</a></li>
<li><a rel="nofollow" class="external text" href="https://github.com/keith-cullen/FreeCoAP">FreeCoAP</a></li>
<li><a rel="nofollow" class="external text" href="https://github.com/obgm/libcoap">libcoap</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="Projects_using_CoAP">Projects using CoAP</h2></div>
<table class="wikitable sortable">
<tbody><tr>
<th>Name</th>
<th>Programming Language</th>
<th>Implemented CoAP version</th>
<th>Client/Server</th>
<th>Implemented CoAP features</th>
<th>License</th>
<th>Link
</th></tr>
<tr>
<td>CoAP Shell</td>
<td>Java</td>
<td>RFC 7252</td>
<td>Client</td>
<td>Observe, Blockwise Transfers, DTLS</td>
<td>Apache License 2.0</td>
<td><a rel="nofollow" class="external free" href="https://github.com/tzolov/coap-shell">https://github.com/tzolov/coap-shell</a>
</td></tr>
<tr>
<td>Copper</td>
<td>JavaScript (browser plugin)</td>
<td>RFC 7252</td>
<td>Client</td>
<td>Observe, Blockwise Transfers</td>
<td>3-clause BSD</td>
<td><a rel="nofollow" class="external free" href="https://github.com/mkovatsc/Copper">https://github.com/mkovatsc/Copper</a> <a rel="nofollow" class="external free" href="https://addons.mozilla.org/firefox/addon/copper-270430/">https://addons.mozilla.org/firefox/addon/copper-270430/</a>
</td></tr>
</tbody></table>
<div class="mw-heading mw-heading2"><h2 id="Inactive_protocol_implementations">Inactive protocol implementations</h2></div>
<table class="wikitable sortable">
<tbody><tr>
<th>Name</th>
<th>Programming Language</th>
<th>Implemented CoAP version</th>
<th>Client/Server</th>
<th>Implemented CoAP features</th>
<th>License</th>
<th>Link
</th></tr>
<tr>
<td>cantcoap</td>
<td>C++/C</td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td></td>
<td>BSD</td>
<td><a rel="nofollow" class="external free" href="https://github.com/staropram/cantcoap">https://github.com/staropram/cantcoap</a>
</td></tr>
<tr>
<td>Canopus</td>
<td><a href="Go_(programming_language)" title="Go (programming language)">Go</a></td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td>Core</td>
<td>Apache License 2.0</td>
<td><a rel="nofollow" class="external free" href="https://github.com/zubairhamed/canopus">https://github.com/zubairhamed/canopus</a>
</td></tr>
<tr>
<td>CoAP implementation for Go</td>
<td><a href="Go_(programming_language)" title="Go (programming language)">Go</a></td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td>Core + Draft Subscribe</td>
<td>MIT</td>
<td><a rel="nofollow" class="external free" href="https://github.com/dustin/go-coap">https://github.com/dustin/go-coap</a>
</td></tr>
<tr>
<td>CoAP.NET</td>
<td>C#</td>
<td>RFC 7252, coap-13, coap-08, coap-03</td>
<td>Client + Server</td>
<td>Core, Observe, Blockwise Transfers</td>
<td>3-clause BSD</td>
<td><a rel="nofollow" class="external free" href="https://github.com/smeshlink/CoAP.NET">https://github.com/smeshlink/CoAP.NET</a>
</td></tr>
<tr>
<td>CoAPthon</td>
<td>Python</td>
<td>RFC 7252</td>
<td>Client + Server + Forward Proxy + Reverse Proxy</td>
<td>Observe, Multicast server discovery, CoRE Link Format parsing, Block-wise</td>
<td>MIT</td>
<td><a rel="nofollow" class="external free" href="https://github.com/Tanganelli/CoAPthon">https://github.com/Tanganelli/CoAPthon</a>
</td></tr>
<tr>
<td>eCoAP</td>
<td>C</td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td>Core</td>
<td>MIT</td>
<td><a rel="nofollow" class="external free" href="https://gitlab.com/jobol/ecoap">https://gitlab.com/jobol/ecoap</a>
</td></tr>
<tr>
<td>Erbium for Contiki</td>
<td>C</td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td>Observe, Blockwise Transfers</td>
<td>3-clause BSD</td>
<td><a rel="nofollow" class="external free" href="http://www.contiki-os.org/">http://www.contiki-os.org/</a> (er-rest-example)
</td></tr>
<tr>
<td>guile-coap</td>
<td>Guile</td>
<td>RFC 7252, RFC 8323</td>
<td>Client + Server</td>
<td></td>
<td>GPL-3.0-or-later</td>
<td><a rel="nofollow" class="external free" href="https://codeberg.org/eris/guile-coap">https://codeberg.org/eris/guile-coap</a>
</td></tr>
<tr>
<td>iCoAP</td>
<td>Objective-C</td>
<td>RFC 7252</td>
<td>Client</td>
<td>Core, Observe, Blockwise Transfers</td>
<td>MIT</td>
<td><a rel="nofollow" class="external free" href="https://github.com/stuffrabbit/iCoAP">https://github.com/stuffrabbit/iCoAP</a>
</td></tr>
<tr>
<td>jCoAP</td>
<td>Java</td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td>Observe, Blockwise Transfers</td>
<td>Apache License 2.0</td>
<td><a rel="nofollow" class="external free" href="https://code.google.com/p/jcoap/">https://code.google.com/p/jcoap/</a>
</td></tr>
<tr>
<td>LibNyoci</td>
<td>C</td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td>Core, Observe, Block, DTLS</td>
<td>MIT</td>
<td><a rel="nofollow" class="external free" href="https://github.com/darconeous/libnyoci">https://github.com/darconeous/libnyoci</a>
</td></tr>
<tr>
<td>microcoap</td>
<td>C</td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td></td>
<td>MIT</td>
<td><a rel="nofollow" class="external free" href="https://github.com/1248/microcoap">https://github.com/1248/microcoap</a>
</td></tr>
<tr>
<td>nCoap</td>
<td>Java</td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td>Observe, Blockwise Transfers, CoRE Link Format, <a rel="nofollow" class="external text" href="https://tools.ietf.org/html/draft-kleine-core-coap-endpoint-id-01">Endpoint-ID-Draft</a></td>
<td>BSD</td>
<td><a rel="nofollow" class="external free" href="https://github.com/okleine/nCoAP">https://github.com/okleine/nCoAP</a>
</td></tr>
<tr>
<td>Ruby coap</td>
<td>Ruby</td>
<td>RFC 7252</td>
<td>Client + Server (david)</td>
<td>Core, Observe, Block, RD</td>
<td>MIT, GPL</td>
<td><a rel="nofollow" class="external free" href="https://github.com/nning/coap">https://github.com/nning/coap</a><br><a rel="nofollow" class="external free" href="https://github.com/nning/david">https://github.com/nning/david</a>
</td></tr>
<tr>
<td>Sensinode C Device Library</td>
<td>C</td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td>Core, Observe, Block, RD</td>
<td>Commercial</td>
<td><a rel="nofollow" class="external free" href="https://silver.arm.com/browse/SEN00">https://silver.arm.com/browse/SEN00</a>
</td></tr>
<tr>
<td>Sensinode Java Device Library</td>
<td>Java SE</td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td>Core, Observe, Block, RD</td>
<td>Commercial</td>
<td><a rel="nofollow" class="external free" href="https://silver.arm.com/browse/SEN00">https://silver.arm.com/browse/SEN00</a>
</td></tr>
<tr>
<td>Sensinode NanoService Platform</td>
<td>Java SE</td>
<td>RFC 7252</td>
<td>Cloud Server</td>
<td>Core, Observe, Block, RD</td>
<td>Commercial</td>
<td><a rel="nofollow" class="external free" href="https://silver.arm.com/browse/SEN00">https://silver.arm.com/browse/SEN00</a>
</td></tr>
<tr>
<td>SwiftCoAP</td>
<td>Swift</td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td>Core, Observe, Blockwise Transfers</td>
<td>MIT</td>
<td><a rel="nofollow" class="external free" href="https://github.com/stuffrabbit/SwiftCoAP">https://github.com/stuffrabbit/SwiftCoAP</a>
</td></tr>
<tr>
<td>TinyOS CoapBlip</td>
<td>nesC/C</td>
<td>coap-13</td>
<td>Client + Server</td>
<td>Observe, Blockwise Transfers</td>
<td>BSD</td>
<td><a rel="nofollow" class="external free" href="https://web.archive.org/web/20130312140509/http://docs.tinyos.net/tinywiki/index.php/CoAP">https://web.archive.org/web/20130312140509/http://docs.tinyos.net/tinywiki/index.php/CoAP</a>
</td></tr>
<tr>
<td>txThings</td>
<td>Python (Twisted)</td>
<td>RFC 7252</td>
<td>Client + Server</td>
<td>Blockwise Transfers, Observe (partial)</td>
<td>MIT</td>
<td><a rel="nofollow" class="external free" href="https://github.com/mwasilak/txThings/">https://github.com/mwasilak/txThings/</a>
</td></tr>
<tr>
<td>YaCoAP</td>
<td>C</td>
<td></td>
<td></td>
<td></td>
<td>MIT</td>
<td><a rel="nofollow" class="external free" href="https://github.com/RIOT-Makers/YaCoAP">https://github.com/RIOT-Makers/YaCoAP</a>
</td></tr>
</tbody></table>
<div class="mw-heading mw-heading2"><h2 id="CoAP_group_communication">CoAP group communication</h2></div>
<p>In many CoAP application domains it is essential to have the ability to address several CoAP resources as a group, instead of addressing each resource individually
(e.g. to turn on all the CoAP-enabled lights in a room with a single CoAP request triggered by toggling the light switch).
To address this need, the IETF has developed an optional extension for CoAP in the form of an experimental RFC: Group Communication for CoAP - RFC 7390<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>
This extension relies on IP multicast to deliver the CoAP request to all group members.
The use of multicast has certain benefits such as reducing the number of packets needed to deliver the request to the members.
However, multicast also has its limitations such as poor reliability and being cache-unfriendly.
An alternative method for CoAP group communication that uses unicasts instead of multicasts relies on having an intermediary where the groups are created.
Clients send their group requests to the intermediary, which in turn sends individual unicast requests to the group members, collects the replies from them, and sends back an aggregated reply to the client.<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Security">Security</h2></div>
<p>CoAP defines four security modes:<sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>
</p>
<ul><li>NoSec, where <a href="DTLS" class="mw-redirect" title="DTLS">DTLS</a> is disabled</li>
<li>PreSharedKey, where DTLS is enabled, there is a list of pre-shared keys, and each key includes a list of which nodes it can be used to communicate with. Devices must support the AES cipher suite.</li>
<li>RawPublicKey, where DTLS is enabled and the device uses an asymmetric key pair without a certificate, which is validated out of band. Devices must support the AES cipher suite and Elliptic Curve algorithms for key exchange.</li>
<li>Certificate, where DTLS is enabled and the device uses <a href="X.509" title="X.509">X.509</a> certificates for validation.</li></ul>
<p>Research has been conducted on optimizing DTLS by implementing security associates as CoAP resources rather than using DTLS as a security wrapper for CoAP traffic. This research has indicated that improvements of up to 6.5 times none optimized implementations.<sup id="cite_ref-Security_as_a_CoAP_resource:_An_optimized_DTLS_implementation_for_the_IoT_6-0" class="reference"><a href="#cite_note-Security_as_a_CoAP_resource:_An_optimized_DTLS_implementation_for_the_IoT-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup>
</p><p>In addition to DTLS, RFC8613<sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> defines the Object Security for Constrained RESTful Environments (OSCORE) protocol which provides security for CoAP at the application layer.
</p>
<div class="mw-heading mw-heading2"><h2 id="Security_issues">Security issues</h2></div>
<p>Although the protocol standard includes provisions for mitigating the threat of <a href="DDoS" class="mw-redirect" title="DDoS">DDoS</a> amplification attacks,<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> these provisions are not implemented in practice,<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> resulting in the presence of over 580,000 targets primarily located in China and attacks up to 320 Gbit/s.<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="Internet_of_Things" class="mw-redirect" title="Internet of Things">Internet of Things</a></li>
<li><a href="OMA_LWM2M" title="OMA LWM2M">OMA Lightweight M2M</a></li>
<li><a href="Web_of_Things" title="Web of Things">Web of Things</a></li>
<li><a href="Static_Context_Header_Compression" title="Static Context Header Compression">Static Context Header Compression (SCHC)</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap"><ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://tools.ietf.org/html/rfc7252">RFC 7252, Constrained Application Protocol (CoAP)</a></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-2">^</a></b></span> <span class="reference-text">"<a rel="nofollow" class="external text" href="http://hinrg.cs.jhu.edu/joomla/images/stories/IPSN_2011_koliti.pdf">Integrating Wireless Sensor Networks with the Web</a> <a rel="nofollow" class="external text" href="https://web.archive.org/web/20170830060917/http://hinrg.cs.jhu.edu/joomla/images/stories/IPSN_2011_koliti.pdf">Archived</a> 2017-08-30 at the <a href="Wayback_Machine" title="Wayback Machine">Wayback Machine</a>" , Walter, Colitti 2011</span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://tools.ietf.org/html/rfc7390">RFC 7390, Group Communication for CoAP</a></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text">"<a rel="nofollow" class="external text" href="http://www.mdpi.com/1424-8220/14/6/9833/htm">Flexible Unicast-Based Group Communication for CoAP-Enabled Devices</a>" , Ishaq, I.; Hoebeke, J.; Van den Abeele, F.; Rossey, J.; Moerman, I.; Demeester, P. Sensors 2014</span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://tools.ietf.org/html/rfc7252">RFC 7252, Constrained Application Protocol (CoAP)</a></span>
</li>
<li id="cite_note-Security_as_a_CoAP_resource:_An_optimized_DTLS_implementation_for_the_IoT-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-Security_as_a_CoAP_resource:_An_optimized_DTLS_implementation_for_the_IoT_6-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFCaposseleCervoDe_CiccoPetrioli2015" class="citation book cs1">Capossele, Angelo; Cervo, Valerio; De Cicco, Gianluca; <a href="Chiara_Petrioli" title="Chiara Petrioli">Petrioli, Chiara</a> (June 2015). "Security as a CoAP resource: An optimized DTLS implementation for the IoT". <i>2015 IEEE International Conference on Communications (ICC)</i>. IEEE. pp. <span class="nowrap">529–</span>554. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FICC.2015.7248379">10.1109/ICC.2015.7248379</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-1-4673-6432-4</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:12568959">12568959</a>.</cite></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-7">^</a></b></span> <span class="reference-text"><cite id="CITEREFPalombiniSeitzSelanderMattsson2019" class="citation journal cs1">Palombini, Francesca; Seitz, Ludwig; Selander, Goeran; Mattsson, John (2019). <a rel="nofollow" class="external text" href="https://tools.ietf.org/html/rfc8613.html">"Object Security for Constrained RESTful Environments (OSCORE)"</a>. <i>tools.ietf.org</i>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC8613">10.17487/RFC8613</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:58380874">58380874</a><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-05-07</span></span>.</cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://blog.cloudflare.com/why-iot-is-insecure/">"TLS 1.3 is going to save us all, and other reasons why IoT is still insecure", Dani Grant, 2017-12-24</a></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-9">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://i.blackhat.com/eu-18/Thu-Dec-6/eu-18-Maggi-When-Machines-Cant-Talk-wp.pdf">"When Machines Can't Talk: Security and Privacy Issues of Machine-to-Machine Data Protocols", Federico Maggi and Rainer Vosseler, 2018-12-06</a></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://www.zdnet.com/article/the-coap-protocol-is-the-next-big-thing-for-ddos-attacks/">"The CoAP protocol is the next big thing for DDoS attacks", Catalin Cimpanu, 2018-12-05</a></span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1290876196">
/* start https://en.wikipedia.org/ */
.mw-parser-output .side-box{margin:4px 0;box-sizing:border-box;border:1px solid #aaa;font-size:88%;line-height:1.25em;background-color:var(--background-color-interactive-subtle,#f8f9fa);display:flow-root}.mw-parser-output .infobox .side-box{font-size:100%}.mw-parser-output .side-box-abovebelow,.mw-parser-output .side-box-text{padding:0.25em 0.9em}.mw-parser-output .side-box-image{padding:2px 0 2px 0.9em;text-align:center}.mw-parser-output .side-box-imageright{padding:2px 0.9em 2px 0;text-align:center}@media(min-width:500px){.mw-parser-output .side-box-flex{display:flex;align-items:center}.mw-parser-output .side-box-text{flex:1;min-width:0}}@media(min-width:720px){.mw-parser-output .side-box{width:238px}.mw-parser-output .side-box-right{clear:right;float:right;margin-left:1em}.mw-parser-output .side-box-left{margin-right:1em}}
/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1237033735">
/* start https://en.wikipedia.org/ */
@media print{body.ns-0 .mw-parser-output .sistersitebox{display:none!important}}@media screen{html.skin-theme-clientpref-night .mw-parser-output .sistersitebox img[src*="Wiktionary-logo-en-v2.svg"]{background-color:white}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .sistersitebox img[src*="Wiktionary-logo-en-v2.svg"]{background-color:white}}
/* end https://en.wikipedia.org/ */
</style><div class="side-box side-box-right sistersitebox"><style data-mw-deduplicate="TemplateStyles:r1126788409">
/* start https://en.wikipedia.org/ */
.mw-parser-output .plainlist ol,.mw-parser-output .plainlist ul{line-height:inherit;list-style:none;margin:0;padding:0}.mw-parser-output .plainlist ol li,.mw-parser-output .plainlist ul li{margin-bottom:0}
/* end https://en.wikipedia.org/ */
</style>
<div class="side-box-flex">
<div class="side-box-image"><span class="noviewer" typeof="mw:File"></span></div>
<div class="side-box-text plainlist">Wikimedia Commons has media related to <span style="font-weight: bold; font-style: italic;"><a href="https://commons.wikimedia.org/wiki/Category:SSL_and_TLS" class="extiw external" title="commons:Category:SSL and TLS">SSL and TLS</a></span>.</div></div>
</div>
<ul><li><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc7252">RFC 7252 "The Constrained Application Protocol (CoAP)"</a></li>
<li><a rel="nofollow" class="external text" href="http://coap.me/">coap.me</a> – CoAP test server run by <a href="University_of_Bremen" title="University of Bremen">University of Bremen</a></li></ul></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-06-27" href="https://en.wikipedia.org/wiki/?title=Constrained_Application_Protocol&oldid=1297577168">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>