Implicit Objects
Explore the implicit objects JSP automatically provides - request, response, session, out, and application - and what each one gives you.
Introduction
You have already used one implicit object without a formal introduction: request, in expressions like request.getParameter("name"). Implicit objects are a set of pre-created Java objects that JSP automatically makes available inside every page - you never declare or instantiate them yourself. This lesson covers the five most important ones in depth: request, response, session, out, and application.
What Are Implicit Objects?
Recall from Lesson 7 that every JSP page is translated into a servlet whose _jspService() method receives the current request and response as parameters. The container declares several local variables at the top of that generated method, pointing to useful objects related to the current request, the session, and the application as a whole. Because they are already declared for you, you can reference them directly inside any scriptlet or expression.
| Implicit Object | Underlying Type | Scope |
|---|---|---|
| request | HttpServletRequest | One HTTP request |
| response | HttpServletResponse | One HTTP request |
| session | HttpSession | One user, across multiple requests |
| out | JspWriter | One HTTP request (writes to the response body) |
| application | ServletContext | Entire web application, shared by all users |
| pageContext | PageContext | Current page only |
| config | ServletConfig | Current servlet configuration |
| page | Object (this) | Current page instance |
| exception | Throwable | Only available on pages with isErrorPage="true" |
request
The request object represents the incoming HTTP request. It is the most frequently used implicit object, giving you access to query parameters, form data, headers, and request-scoped attributes set by a Servlet.
<% String username = request.getParameter("username"); String userAgent = request.getHeader("User-Agent"); String method = request.getMethod();%><p>Username: <%= username %></p><p>HTTP Method: <%= method %></p><p>Browser: <%= userAgent %></p>Click Run to see what this code prints.
response
The response object represents the outgoing HTTP response. While out (covered below) is normally used for writing body content, response is used for lower-level control, such as redirecting the browser or setting response headers.
<% boolean loggedIn = (session.getAttribute("user") != null); if (!loggedIn) { response.sendRedirect("login.jsp"); return; }%><p>Welcome back!</p>After calling response.sendRedirect(...), the rest of the page still runs unless you explicitly stop it - using return; inside the scriptlet, as shown above, prevents the page from continuing to generate output that will never actually be shown.
session
The session object represents an HttpSession, letting you store data that should persist for a single user across multiple requests - such as login state or a shopping cart. Data stored here is unique per browser/user, unlike application (covered next), which is shared by everyone.
<% // On a login page, after verifying credentials: session.setAttribute("user", "Asha");%><% // On any later page during the same session: String currentUser = (String) session.getAttribute("user");%><p>Logged in as: <%= currentUser %></p>out
The out object is a JspWriter used to write content directly into the response body from a scriptlet. Static HTML and expressions are already converted into out.write()/out.print() calls behind the scenes (as you saw in Lesson 7), but you can also call out explicitly for more control.
<% out.println("<ul>"); for (int i = 1; i <= 3; i++) { out.println("<li>Item " + i + "</li>"); } out.println("</ul>");%>Click Run to see what this code prints.
application
The application object represents the ServletContext, which is shared by every user and every page across the entire web application, for as long as the application stays deployed. It is commonly used for application-wide configuration values or simple shared counters (with appropriate care for concurrency).
<% Integer totalVisits = (Integer) application.getAttribute("totalVisits"); if (totalVisits == null) { totalVisits = 0; } totalVisits++; application.setAttribute("totalVisits", totalVisits);%><p>Total visits across all users: <%= totalVisits %></p>session data belongs to one user's browser and lasts only for that session. application data is shared globally by every user of the deployed web application. Choosing the wrong scope is a very common beginner bug.
The Remaining Implicit Objects
JSP defines four more implicit objects beyond the five covered in depth above. You will encounter these less often, but it is worth knowing what each one is for.
- pageContext - provides access to all the other scopes (page, request, session, application) through one unified API, and is heavily used internally by JSTL and custom tags.
- config - gives access to servlet initialization parameters configured in web.xml for this specific page/servlet.
- page - a reference to the current page instance itself (equivalent to this), rarely used directly.
- exception - only available on a page marked isErrorPage="true", giving access to the Throwable that caused the error, as shown in the previous lesson.
Common Mistakes
- Storing per-user data (like a shopping cart) in application instead of session, leaking one user's data to everyone.
- Forgetting that request attributes only survive a single request/forward, not across separate page loads.
- Mutating shared data in application without any thread-safety consideration, causing subtle bugs under load.
- Continuing to generate output after calling response.sendRedirect() without a return statement.
Best Practices
- Use request attributes to pass data from a Servlet to a JSP view for a single request/forward.
- Use session for anything specific to one logged-in user across multiple pages.
- Use application sparingly, mainly for read-mostly, application-wide configuration rather than frequently changing data.
- Prefer implicit objects together with Expression Language (${ }) in modern JSP rather than scriptlets, as you will see in the next lesson.
Frequently Asked Questions
No. These are automatically declared by the container inside the generated _jspService() method - you can use them directly in any scriptlet or expression without any import or setup.
request scope lasts only for a single HTTP request (and any forwards during it). session scope persists across many requests from the same user until the session expires or is invalidated.
You generally should not mix them - out is JSP's buffered writer for the page, and calling response.getWriter() directly can conflict with it. Stick to out inside JSP pages.
Yes, by default application-scoped data is stored in memory and is lost on server restart or redeployment, unless you explicitly persist it somewhere like a database.
Key Takeaways
- Implicit objects are pre-declared by the container and available in every JSP page without setup.
- request holds data about the current HTTP request, including parameters and headers.
- response controls the outgoing HTTP response, such as redirects and headers.
- session stores data specific to one user across multiple requests.
- application shares data across the entire web application for all users.
- out writes content directly into the response body.
Summary
Implicit objects give every JSP page instant access to the current request, response, session, output stream, and application context, without any manual setup. Understanding their different scopes - request, session, and application - is essential for avoiding data-leak bugs between users. Next, you will learn Expression Language (EL), the modern ${ } syntax that lets you read these objects' data without writing scriptlets at all.