# Hono v4.13.0 - Product: Hono (https://whatsnew.fyi/product/hono) - Vendor: Hono - Date: 2026-08-03 - Version: v4.13.0 - Original notes: https://github.com/honojs/hono/releases/tag/v4.13.0 - Permalink: https://whatsnew.fyi/product/hono/releases/v4.13.0 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — First-class support for the HTTP QUERY method with app.query() handler - **added** — Method Not Allowed middleware that returns 405 responses with Allow header for unsupported methods on registered routes - **changed** — Core request/response path optimizations including skipping unnecessary Headers allocations, replacing regex tests with indexOf, and lazy allocation of internal state, achieving up to 1.25x performance improvement on common routes - **changed** — Cache Middleware now caches QUERY responses using SHA-256 digest of request content as part of the cache key, changing internal cache key format for all methods - **changed** — ETag Middleware now handles conditional requests for QUERY, returning 304 Not Modified when If-None-Match matches - **changed** — CORS Middleware default Access-Control-Allow-Methods now includes QUERY: GET, HEAD, PUT, POST, DELETE, PATCH, QUERY - **changed** — RegExpRouter now detects unsupported path combinations at registration time instead of at first matching request, making registration plus first match roughly 20% faster - **changed** — JWT and JWK middleware now accept realm option for WWW-Authenticate challenge on 401 responses with properly escaped challenge values - **changed** — JSX RefObject type is now aligned with React 19 as { current: T }, requiring nullable refs to be typed as RefObject and useRef(undefined) instead of useRef() - **changed** — Compress Middleware now sets Vary: Accept-Encoding on negotiated responses - **fixed** — JSX function components can now return an array of children without throwing during server-side rendering - **changed** — hono/utils/headers synced with IANA HTTP Field Name Registry, adding newly registered fields such as Accept-Query Hono v4.13.0 is now available! The highlight of this release is performance: a batch of low-level optimizations makes the core request/response path significantly faster — up to 1.25x on common routes in our benchmark. This release also adds first-class support for the HTTP QUERY method, defined in [RFC 10008](https://www.rfc-editor.org/rfc/rfc10008.html), a new Method Not Allowed middleware, and more. ##### Performance improvements This release includes a series of small optimizations: skipping unnecessary `Headers` allocations, replacing regex tests with `indexOf`, allocating internal state lazily, and more. Here is [`benchmarks/fetch`](https://github.com/honojs/hono/tree/main/benchmarks/fetch) comparing v4.12 and v4.13 (`ROUNDS=5 ./compare.sh`, Bun 1.4.0, Apple Silicon — each measurement runs in a fresh process, and the variant order is reversed every round to avoid warm-up bias): | Benchmark | v4.12 | v4.13 | Speedup | | --- | ---: | ---: | ---: | | `ping` — `GET /` | 165.83 ns | 163.99 ns | 1.01x | | `query` — `GET /id/1?name=bun` | 674.40 ns | 616.99 ns | **1.09x** | | `json` — `GET /user` | 528.99 ns | 422.44 ns | **1.25x** | | `body` — `POST /json` | 1.16 µs | 1.00 µs | **1.15x** | The individual changes: - perf(context): iterate the header record with `for..in` https://github.com/honojs/hono/pull/5118 - perf(url): replace regex tests with `indexOf` https://github.com/honojs/hono/pull/5121 - perf(context): skip `Headers` creation when there are no headers to merge https://github.com/honojs/hono/pull/5122 - perf(urls): refactor `tryDecodeURIComponent` https://github.com/honojs/hono/pull/5158 - perf(request): allocate `#validatedData` lazily https://github.com/honojs/hono/pull/5175 - perf(request): probe the body cache without allocating https://github.com/honojs/hono/pull/5176 In addition, the RegExpRouter rewrite described below makes route registration plus the first match roughly 20% faster. Thanks @kibertoad for the contributions! ##### First-class QUERY method support The QUERY method — a safe, idempotent method that carries a request body — is now a first-class citizen in Hono. You can define QUERY handlers with `app.query()`: ```ts const app = new Hono() app.query('/search', async (c) => { const conditions = await c.req.json() return c.json(await search(conditions)) }) ``` Thanks @shellhaki! ##### QUERY support across built-in middleware The built-in middleware has been updated to handle QUERY requests properly: ###### Cache Middleware The Cache Middleware now caches QUERY responses. Following RFC 10008 Section 2.7, the cache key incorporates a SHA-256 digest of the request content and its representation metadata, so different query bodies are cached separately: ```ts app.query( '/search', cache({ cacheName: 'search-cache', cacheControl: 'max-age=3600', }) ) ``` **Note**: To support this, the internal cache key format has changed for all methods, including GET. Cached entries are now stored under an internal URL of the form `/.hono/cache?__hono_cache_key=...`. If you purge cache entries by URL outside of the middleware (e.g. calling `caches.delete()` with the original request URL), you will need to update that logic. Existing cache entries stored with the old format will simply be re-fetched. ###### ETag Middleware The ETag Middleware now handles conditional requests for QUERY, returning `304 Not Modified` when `If-None-Match` matches. ###### CORS Middleware The CORS Middleware now includes QUERY in the default `Access-Control-Allow-Methods`, which is now `GET, HEAD, PUT, POST, DELETE, PATCH, QUERY`. If you specify `allowMethods` explicitly, nothing changes for you. Thanks @usualoma and @Cherry! ##### Method Not Allowed Middleware The new Method Not Allowed Middleware returns a `405 Method Not Allowed` response with a proper `Allow` header when the request path matches a registered route but t _[Truncated at 4000 characters — full notes: https://github.com/honojs/hono/releases/tag/v4.13.0]_