packageurls
← Blog

2026-09-24 · Teo Varga

What go get actually asks your domain

When you run go get go.oakfield.dev/ledger, the go tool does not know where the code lives. It makes one HTTPS request to find out:

GET https://go.oakfield.dev/ledger?go-get=1

It reads the response for a single tag:

<meta name="go-import"
      content="go.oakfield.dev/ledger git https://github.com/oakfield/ledger">

Three fields: the import prefix, the version control system, and the repository root. That is the whole protocol. Everything after it is ordinary git.

Because the tag is the only thing the go tool reads, the repository can move without the import path changing. Update the third field and the next go get follows it. Nobody who imports your package has to do anything.

Two details worth knowing. The prefix matches subpackages too: a request for go.oakfield.dev/ledger/internal/x?go-get=1 gets the same tag. And a request without ?go-get=1 is a human in a browser, so we redirect them to the repository instead.

Package URLs serves that tag for you, over TLS, on a hostname you own. That is all it does.