Web
HTTP Headers Cheat Sheet — Request, Response, and Security Headers
Headers carry the metadata that makes HTTP work — what format the body is in, how long it can be cached, who may read it. This reference covers the ones you meet most often.
Put it into practice with the matching tool.
Look up a status code →Advertisement
Request headers
AcceptFormats the client can handle, e.g. application/jsonAccept-EncodingCompression the client supports, e.g. gzip, brAccept-LanguagePreferred languagesAuthorizationCredentials, e.g. Bearer <token> or Basic <base64>Content-TypeFormat of the request body being sentCookieCookies previously set by the serverHostTarget hostname — required in HTTP/1.1OriginOrigin of the page making the request — drives CORSRefererPage the request came from (spelling is historic)User-AgentIdentifies the client softwareIf-None-MatchSend the saved ETag to revalidate a cached copyIf-Modified-SinceRevalidate by timestamp insteadRangeRequest only part of a resourceResponse headers
Content-TypeFormat of the response body — include charset for textContent-LengthSize of the body in bytesContent-EncodingCompression applied, e.g. gzip or brContent-Dispositionattachment; filename="x.pdf" triggers a downloadLocationWhere to go — used with 3xx redirectsSet-CookieSets a cookie on the clientRetry-AfterWhen to try again — used with 429 and 503ServerServer software — often best omittedVaryWhich request headers change the response, for cachesCaching
Cache-Control: no-storeNever cache — for sensitive responsesCache-Control: no-cacheCache, but revalidate before each useCache-Control: max-age=3600Fresh for one hourCache-Control: public, max-age=31536000, immutableFor fingerprinted static assetsCache-Control: privateOnly the browser may cache, not shared cachess-maxage=600Separate lifetime for CDNs and shared cachesstale-while-revalidate=60Serve stale briefly while refreshing in the backgroundETagVersion identifier used for revalidationLast-ModifiedTimestamp used for revalidationCORS
Access-Control-Allow-OriginWhich origin may read the responseAccess-Control-Allow-MethodsMethods allowed — answers the preflightAccess-Control-Allow-HeadersRequest headers the client may sendAccess-Control-Allow-CredentialsPermit cookies — cannot combine with *Access-Control-Expose-HeadersResponse headers JavaScript may readAccess-Control-Max-AgeHow long the preflight result can be cachedCookie attributes
HttpOnlyHidden from JavaScript — blocks theft via XSSSecureOnly sent over HTTPSSameSite=LaxSent on top-level navigation only — a good defaultSameSite=StrictNever sent on cross-site requestsSameSite=NoneSent cross-site — requires SecureMax-Age=3600Lifetime in secondsPath=/ ; Domain=Scope of the cookieSecurity headers
Content-Security-PolicyRestricts where scripts, styles, and frames may load fromStrict-Transport-Securitymax-age=31536000 forces HTTPS on future visitsX-Content-Type-Options: nosniffStops the browser guessing content typesX-Frame-Options: DENYBlocks framing — superseded by frame-ancestorsReferrer-PolicyHow much referrer information to leakPermissions-PolicyDisables browser features such as camera or geolocationCross-Origin-Opener-PolicyIsolates the browsing context from cross-origin windows