HTTP headers are the labelled lines sent before the body of every request and response. They carry the content type, caching rules, cookies, credentials and security policies. See the headers any site sends with the HTTP Headers Viewer, and grade a site's security headers with the Security Headers Analyzer.
Request headers
| Header | Purpose |
|---|---|
Host |
The site being requested (required in HTTP/1.1) |
User-Agent |
Identifies the browser or client program |
Accept |
Content types the client can handle, such as text/html or application/json |
Accept-Language |
Preferred languages, for example es-ES,es;q=0.9,en;q=0.8 |
Accept-Encoding |
Compression the client understands (gzip, br) |
Authorization |
Credentials, such as Bearer <token> or Basic <base64> |
Cookie |
Cookies the browser sends back to the site |
Content-Type |
Format of the request body (application/json, multipart/form-data) |
Origin |
Where a cross-site request came from; used by CORS and CSRF checks |
Referer |
The previous page (the misspelling is historical) |
If-None-Match |
Send the body only if the ETag changed |
Range |
Ask for part of a file, such as bytes=0-1023 |
Response headers
| Header | Purpose |
|---|---|
Content-Type |
Format of the body, with charset for text: text/html; charset=utf-8 |
Content-Length |
Size of the body in bytes |
Content-Encoding |
Compression applied to the body (gzip, br) |
Location |
Where to go next, used with 201 and the 3xx redirects |
Set-Cookie |
Stores a cookie (see the attributes below) |
WWW-Authenticate |
How to authenticate after a 401 |
Retry-After |
When to try again after 429 or 503 (seconds or a date) |
ETag |
A version tag for the content, for cache validation |
Last-Modified |
When the content last changed |
Vary |
Request headers that change the response, so caches keep separate copies (Vary: Accept-Encoding) |
Cache-Control
| Directive | Meaning |
|---|---|
max-age=<seconds> |
Fresh for this many seconds, no questions asked |
s-maxage=<seconds> |
Like max-age, but for shared caches such as CDNs |
no-cache |
May be stored, but must be revalidated with the server before each reuse |
no-store |
Never store it anywhere (sensitive data) |
public / private |
private means only the user's own browser may keep it, not shared caches |
immutable |
The file will never change at this URL, so skip revalidation |
must-revalidate |
Once stale, never serve it without checking with the server |
stale-while-revalidate=<seconds> |
Serve the stale copy while fetching a fresh one in the background |
Common recipes: fingerprinted static files (app.3f9a1c.js) use public, max-age=31536000, immutable; HTML pages use no-cache; personal data uses no-store.
Security headers
| Header | Typical value | Purpose |
|---|---|---|
Strict-Transport-Security |
max-age=31536000; includeSubDomains |
Makes browsers use HTTPS only for this site |
Content-Security-Policy |
default-src 'self' |
Limits where scripts, styles and images may load from; the main defence against XSS |
X-Content-Type-Options |
nosniff |
Stops browsers guessing a different content type |
X-Frame-Options |
DENY or SAMEORIGIN |
Blocks the page being framed (CSP frame-ancestors is the modern equivalent) |
Referrer-Policy |
strict-origin-when-cross-origin |
Controls how much of the URL is sent in Referer |
Permissions-Policy |
camera=(), microphone=() |
Switches off browser features the page does not need |
The CSP Header Generator helps build a policy, and Content Security Policy (CSP) explains what it protects against.
Cookie attributes
Set with Set-Cookie: name=value; Secure; HttpOnly; SameSite=Lax.
| Attribute | Meaning |
|---|---|
Secure |
Only sent over HTTPS |
HttpOnly |
Hidden from JavaScript, which limits what an XSS attack can steal |
SameSite=Lax | Strict | None |
Controls sending the cookie on cross-site requests; Lax is a sensible default and None needs Secure |
Max-Age / Expires |
How long it lives; without them it ends with the browser session |
Domain / Path |
Which hosts and paths receive it |
CORS headers
Browsers block a page from reading another origin's response unless that origin opts in. For anything beyond a simple request the browser first sends a OPTIONS preflight.
| Header | Purpose |
|---|---|
Access-Control-Allow-Origin |
Which origin may read the response (* for any, or one exact origin) |
Access-Control-Allow-Methods |
Methods allowed in a preflight reply |
Access-Control-Allow-Headers |
Request headers allowed in a preflight reply |
Access-Control-Allow-Credentials |
true lets the request carry cookies; it cannot be combined with * |
Header names are case-insensitive (content-type is the same as Content-Type), but their values often are not. For status codes, see HTTP Status Codes Cheat Sheet.