elefcode
← All cheat sheets

Web

HTTP Headers Cheat Sheet — Request, Response, and Security Headers

Headers carry the metadata that makes HTTP work — what format the body is in, how long it can be cached, who may read it. This reference covers the ones you meet most often.

Put it into practice with the matching tool.

Look up a status code →

Advertisement

Request headers

AcceptFormats the client can handle, e.g. application/json
Accept-EncodingCompression the client supports, e.g. gzip, br
Accept-LanguagePreferred languages
AuthorizationCredentials, e.g. Bearer <token> or Basic <base64>
Content-TypeFormat of the request body being sent
CookieCookies previously set by the server
HostTarget hostname — required in HTTP/1.1
OriginOrigin of the page making the request — drives CORS
RefererPage the request came from (spelling is historic)
User-AgentIdentifies the client software
If-None-MatchSend the saved ETag to revalidate a cached copy
If-Modified-SinceRevalidate by timestamp instead
RangeRequest only part of a resource

Response headers

Content-TypeFormat of the response body — include charset for text
Content-LengthSize of the body in bytes
Content-EncodingCompression applied, e.g. gzip or br
Content-Dispositionattachment; filename="x.pdf" triggers a download
LocationWhere to go — used with 3xx redirects
Set-CookieSets a cookie on the client
Retry-AfterWhen to try again — used with 429 and 503
ServerServer software — often best omitted
VaryWhich request headers change the response, for caches

Caching

Cache-Control: no-storeNever cache — for sensitive responses
Cache-Control: no-cacheCache, but revalidate before each use
Cache-Control: max-age=3600Fresh for one hour
Cache-Control: public, max-age=31536000, immutableFor fingerprinted static assets
Cache-Control: privateOnly the browser may cache, not shared caches
s-maxage=600Separate lifetime for CDNs and shared caches
stale-while-revalidate=60Serve stale briefly while refreshing in the background
ETagVersion identifier used for revalidation
Last-ModifiedTimestamp used for revalidation

CORS

Access-Control-Allow-OriginWhich origin may read the response
Access-Control-Allow-MethodsMethods allowed — answers the preflight
Access-Control-Allow-HeadersRequest headers the client may send
Access-Control-Allow-CredentialsPermit cookies — cannot combine with *
Access-Control-Expose-HeadersResponse headers JavaScript may read
Access-Control-Max-AgeHow long the preflight result can be cached

Cookie attributes

HttpOnlyHidden from JavaScript — blocks theft via XSS
SecureOnly sent over HTTPS
SameSite=LaxSent on top-level navigation only — a good default
SameSite=StrictNever sent on cross-site requests
SameSite=NoneSent cross-site — requires Secure
Max-Age=3600Lifetime in seconds
Path=/ ; Domain=Scope of the cookie

Security headers

Content-Security-PolicyRestricts where scripts, styles, and frames may load from
Strict-Transport-Securitymax-age=31536000 forces HTTPS on future visits
X-Content-Type-Options: nosniffStops the browser guessing content types
X-Frame-Options: DENYBlocks framing — superseded by frame-ancestors
Referrer-PolicyHow much referrer information to leak
Permissions-PolicyDisables browser features such as camera or geolocation
Cross-Origin-Opener-PolicyIsolates the browsing context from cross-origin windows

More cheat sheets