Skip to main content
Working with an HTTP(S) server depends on how the dictionary is stored in memory. If the dictionary is stored using cache and complex_key_cache, ClickHouse requests the necessary keys by sending a request via the POST method. Example of settings:

In order for ClickHouse to access an HTTPS resource, you must configure openSSL in the server configuration. Setting fields: When creating a dictionary using the DDL command (CREATE DICTIONARY ...) remote hosts for HTTP dictionaries are checked against the contents of remote_url_allow_hosts section from config to prevent database users to access arbitrary HTTP server. The headers, including their names, are shown as HEADERS ('[HIDDEN]') in the output of SHOW CREATE DICTIONARY, in system.tables and in the query logs, the same way as the password. As with the password, a query that cannot be parsed is logged as is, with only query_masking_rules applied. To display the headers in SHOW CREATE DICTIONARY and system.tables, enable the server setting display_secrets_in_show_and_select and the format setting format_display_secrets_in_show_and_select; the user also needs the displaySecretsInShowAndSelect privilege. These settings do not affect the query logs.
Last modified on October 1, 2026