Skip to content

HTTP Security Headers Explained

The response headers that control content isolation, framing, referrer leakage, feature access, and transport security, with the value that holds for each.

These headers tell the browser how the page may be framed, isolated, and leaked from. One wrong value silently weakens them: unsafe-inline empties a CSP, max-age=0 disables HSTS, and unsafe-none hands the page to any cross-origin opener. The example column shows the value that holds.

Reference table · 21 entries
21 of 21 rows
Content isolation
Content-Security-PolicyWhitelists the sources the page may load scripts, styles, and frames from.default-src 'self'; script-src 'self'
Content-Security-Policy-Report-OnlyReports violations without blocking; the staging step before enforcing.default-src 'self'; report-uri /csp
CSP sandboxApplies sandbox restrictions to the whole document, not just an iframe.Content-Security-Policy: sandbox allow-scripts
X-Content-Type-OptionsStops the browser from sniffing a content type other than the declared one.nosniff
Cross-Origin-Opener-PolicyCuts script access between the page and the cross-origin windows it opens.same-origin
Cross-Origin-Embedder-PolicyLets the page load only cross-origin resources that opt in through CORP or CORS.require-corp
Cross-Origin-Embedder-Policy: credentiallessLoads no-CORS resources without CORP by stripping credentials from them.credentialless
Cross-Origin-Resource-PolicyOpts a resource out of being embedded by cross-origin pages.same-origin
Framing
X-Frame-Options: DENYBlocks every site, including the page's own origin, from framing it.DENY
X-Frame-Options: SAMEORIGINAllows framing only by pages on the page's own origin.SAMEORIGIN
CSP frame-ancestorsNames the sources that may frame the page; supersedes X-Frame-Options when both are set.frame-ancestors 'none'
X-Frame-Options: ALLOW-FROMObsolete; modern browsers ignore it. Use frame-ancestors instead.ALLOW-FROM https://example.com (ignored)
Referrer & permissions
Referrer-PolicyLimits the URL the browser sends as a referrer on outgoing requests.strict-origin-when-cross-origin
Referrer-Policy: no-referrerStrips the referrer from every outgoing request.no-referrer
Permissions-PolicyGrants or blocks browser features per origin.camera=(), geolocation=(self)
Permissions-Policy delegationIframes inherit the policy unless the embedder hands the feature over with the allow attribute.<iframe allow="camera *">
Transport
Strict-Transport-SecurityForces HTTPS for the host for max-age seconds.max-age=31536000
HSTS includeSubDomainsExtends the HTTPS rule to every subdomain; breaks subdomains still on plain HTTP.max-age=31536000; includeSubDomains
HSTS preloadOpts the host into the browser preload list, closing the first-visit gap.max-age=31536000; includeSubDomains; preload
HSTS rollbackmax-age=0 lifts the policy for browsers; preload removal takes months.max-age=0
CSP upgrade-insecure-requestsRewrites every http:// subresource request to https:// before it leaves the page.upgrade-insecure-requests