Skip to content

HTTP Headers Explained

A reference for the request and response headers that negotiate content, security, caching, and identity on every HTTP exchange.

Every request and response carries headers that negotiate content, security, caching, and identity. Use these fields to control how clients and servers exchange data.

Reference table · 58 entries
58 of 58 rows
Request
Names the server and port the request targets.developer.mozilla.org
Identifies the client software making the request.Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)
Declares the media types the client can process.text/html,application/xhtml+xml,application/json
Carries credentials that authenticate the client.Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9
Sends stored cookies back to the origin server.sessionid=38afes7a8; theme=dark
Gives the URL of the page that linked here.https://example.com/docs/index.html
Lists the compression encodings the client accepts.gzip, deflate, br
Ranks the natural languages the client prefers.en-US,en;q=0.9
Names the origin that started the request.https://example.com
Asks for only part of the body, given as a byte range.bytes=0-1023
Lists the client and proxy IPs along the request path.203.0.113.45, 70.41.3.18
Tells the origin which protocol the client used.https
Carries the proxy path in one standard field.for=203.0.113.45;proto=https
Controls whether the connection stays open after this exchange.keep-alive
States what the server must confirm before the client sends the body.100-continue
Limits how many proxies may forward a TRACE request.3
Response
Declares the media type of the body on requests and responses.text/html; charset=utf-8
Gives the size of the body in bytes.3489
Directs how caches store the request or response.no-cache
Tells the browser to store a cookie.id=a3fWa; Expires=Wed, 21 Oct 2026 07:28:00 GMT; HttpOnly
Names the URL for a redirect target.https://example.com/new-location
Gives a version tag for the body, used by conditional requests."33a64df551425fcc55e4d42da148ef95"
Gives the date and time the body last changed.Wed, 21 Oct 2025 07:28:00 GMT
Lists the request headers a cached response depends on.Accept-Encoding
Names the compression applied to the body.gzip
Names the wire format used to move the body.chunked
Tells the client how long to wait before the next request.120
Lists the methods the resource supports.GET, POST, HEAD
Reports how long the response has spent in a cache.2463
Names the server software behind the response.cloudflare
Gives the time the response was produced.Wed, 21 Oct 2025 07:28:00 GMT
Conditional
Asks for a fresh body only if the ETag changed."33a64df551425fcc55e4d42da148ef95"
Requests the body only if it changed since the date.Wed, 21 Oct 2025 07:28:00 GMT
Makes the request succeed only when the ETag matches."33a64df551425fcc55e4d42da148ef95"
Makes the request succeed only when the body is unchanged since the date.Wed, 21 Oct 2025 07:28:00 GMT
Applies the Range only when the ETag or date still matches."33a64df551425fcc55e4d42da148ef95"
Security
Forces HTTPS for future requests to this host.max-age=31536000; includeSubDomains
Whitelists the sources the browser may load.default-src 'self'; script-src 'self'
Stops other sites from framing this page; superseded by the CSP frame-ancestors directive, which browsers honor instead when both are set.DENY
Stops the browser from guessing a different content type.nosniff
Limits the referrer data sent with outgoing requests.strict-origin-when-cross-origin
Grants or blocks browser features, such as camera or geolocation.camera=(), geolocation=(self)
Isolates the page from cross-origin browser windows.same-origin
CORS
Names which origin may read the response.https://example.com
Lists the HTTP methods permitted in CORS.GET, POST, OPTIONS
Lists request headers allowed in CORS.Content-Type, Authorization
Lets credentialed requests read the response.true
Lists response headers the page may read from script.X-Request-Id, Content-Length
Sets how long the browser caches the preflight result.600
Tells the server which method the real request will use.DELETE
Tells the server which headers the real request will send.Content-Type, Authorization
Lets the named origin read detailed resource timing data.https://example.com
Content
Tells the browser to show the body or save it as a file.attachment; filename="report.pdf"
Reports which byte range a partial body covers.bytes 0-1023/146515
Tells the client the server accepts byte range requests.bytes
Points to related resources, such as the next page.</page/2>; rel="next"
Points to another service endpoint, such as HTTP/3.h3=":443"; ma=86400
Names the auth scheme the server requires after a 401.Bearer realm="api"