Cheat Sheets Web & HTTP

HTTP Headers Cheat Sheet

Request and response headers, Cache-Control directives, security headers, cookie attributes and CORS headers, each with what it does and typical values.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page
On this page

HTTP headers are the labelled lines sent before the body of every request and response. They carry the content type, caching rules, cookies, credentials and security policies. See the headers any site sends with the HTTP Headers Viewer, and grade a site's security headers with the Security Headers Analyzer.

Request headers

Header Purpose
Host The site being requested (required in HTTP/1.1)
User-Agent Identifies the browser or client program
Accept Content types the client can handle, such as text/html or application/json
Accept-Language Preferred languages, for example es-ES,es;q=0.9,en;q=0.8
Accept-Encoding Compression the client understands (gzip, br)
Authorization Credentials, such as Bearer <token> or Basic <base64>
Cookie Cookies the browser sends back to the site
Content-Type Format of the request body (application/json, multipart/form-data)
Origin Where a cross-site request came from; used by CORS and CSRF checks
Referer The previous page (the misspelling is historical)
If-None-Match Send the body only if the ETag changed
Range Ask for part of a file, such as bytes=0-1023

Response headers

Header Purpose
Content-Type Format of the body, with charset for text: text/html; charset=utf-8
Content-Length Size of the body in bytes
Content-Encoding Compression applied to the body (gzip, br)
Location Where to go next, used with 201 and the 3xx redirects
Set-Cookie Stores a cookie (see the attributes below)
WWW-Authenticate How to authenticate after a 401
Retry-After When to try again after 429 or 503 (seconds or a date)
ETag A version tag for the content, for cache validation
Last-Modified When the content last changed
Vary Request headers that change the response, so caches keep separate copies (Vary: Accept-Encoding)

Cache-Control

Directive Meaning
max-age=<seconds> Fresh for this many seconds, no questions asked
s-maxage=<seconds> Like max-age, but for shared caches such as CDNs
no-cache May be stored, but must be revalidated with the server before each reuse
no-store Never store it anywhere (sensitive data)
public / private private means only the user's own browser may keep it, not shared caches
immutable The file will never change at this URL, so skip revalidation
must-revalidate Once stale, never serve it without checking with the server
stale-while-revalidate=<seconds> Serve the stale copy while fetching a fresh one in the background

Common recipes: fingerprinted static files (app.3f9a1c.js) use public, max-age=31536000, immutable; HTML pages use no-cache; personal data uses no-store.

Security headers

Header Typical value Purpose
Strict-Transport-Security max-age=31536000; includeSubDomains Makes browsers use HTTPS only for this site
Content-Security-Policy default-src 'self' Limits where scripts, styles and images may load from; the main defence against XSS
X-Content-Type-Options nosniff Stops browsers guessing a different content type
X-Frame-Options DENY or SAMEORIGIN Blocks the page being framed (CSP frame-ancestors is the modern equivalent)
Referrer-Policy strict-origin-when-cross-origin Controls how much of the URL is sent in Referer
Permissions-Policy camera=(), microphone=() Switches off browser features the page does not need

The CSP Header Generator helps build a policy, and Content Security Policy (CSP) explains what it protects against.

Set with Set-Cookie: name=value; Secure; HttpOnly; SameSite=Lax.

Attribute Meaning
Secure Only sent over HTTPS
HttpOnly Hidden from JavaScript, which limits what an XSS attack can steal
SameSite=Lax | Strict | None Controls sending the cookie on cross-site requests; Lax is a sensible default and None needs Secure
Max-Age / Expires How long it lives; without them it ends with the browser session
Domain / Path Which hosts and paths receive it

CORS headers

Browsers block a page from reading another origin's response unless that origin opts in. For anything beyond a simple request the browser first sends a OPTIONS preflight.

Header Purpose
Access-Control-Allow-Origin Which origin may read the response (* for any, or one exact origin)
Access-Control-Allow-Methods Methods allowed in a preflight reply
Access-Control-Allow-Headers Request headers allowed in a preflight reply
Access-Control-Allow-Credentials true lets the request carry cookies; it cannot be combined with *

Header names are case-insensitive (content-type is the same as Content-Type), but their values often are not. For status codes, see HTTP Status Codes Cheat Sheet.

Try these tools

See also

  • Glossary Content Security Policy (CSP)
    A Content Security Policy is an HTTP header that tells the browser which sources of scripts, styles.
  • Glossary CORS
    CORS (Cross-Origin Resource Sharing) is the browser mechanism that lets a server allow web pages from other origins to read its responses.
  • Glossary Cookie
    A cookie is a small piece of data a website stores in your browser and sends back with later requests.
  • Cheat sheet HTTP Status Codes Cheat Sheet
    The HTTP status codes you will actually meet, grouped by class, with the pairs people confuse (401 vs 403.
  • Cheat sheet MIME Types Cheat Sheet
    The MIME types for web pages, data, images, audio, video, fonts and archives.
AdSense Placeholder
Slot: footer_leaderboard