HTTP headers are the name-value lines at the top of every request and response. There are hundreds; these are the ones you'll actually meet while building or debugging a website, grouped by job, each with what it does and a typical value.
GET /api/orders HTTP/1.1
Host: shop.example.com
Accept: application/json
Authorization: Bearer eyJhbGciOi...
Cookie: session=4f2a...
HTTP/1.1 200 OK
Content-Type: application/json; charset=utf-8
Cache-Control: private, no-cache
Set-Cookie: session=4f2a...; Secure; HttpOnly; SameSite=Lax
Names are case-insensitive. HTTP/2 and HTTP/3 send them in lower case, which is why DevTools often shows content-type.
| Header | What it does | Example |
|---|---|---|
Host | Which site on the server you want. Required in HTTP/1.1. | shop.example.com |
User-Agent | Identifies the browser or client. See yours. | Mozilla/5.0 (Windows NT 10.0; ...) Chrome/129.0 |
Accept | Formats the client can read, in order of preference. | application/json |
Accept-Language | Preferred languages. | en-US,en;q=0.9 |
Accept-Encoding | Compression the client supports. | gzip, deflate, br, zstd |
Authorization | Credentials, usually a token. Decode a JWT. | Bearer eyJhbGciOi... |
Cookie | Cookies the browser stored for this site. | session=4f2a; theme=dark |
Content-Type | Format of the request body. | application/json |
Content-Length | Size of the body in bytes. | 348 |
Referer | The page the request came from (one r, a historic typo). Explained. | https://blog.example.com/ |
Origin | The origin that started a cross-origin or POST request. Used by CORS and CSRF checks. | https://app.example.com |
If-None-Match | Only send the body if the ETag changed; otherwise the server answers 304. | "33a64df5" |
If-Modified-Since | Only send the body if it changed after this date. | Tue, 24 Sep 2026 10:00:00 GMT |
Cache-Control | In a request: asks caches for a fresh copy. | no-cache |
Range | Ask for part of a file (video seeking, resumed downloads). | bytes=0-1023 |
Sec-Fetch-Site | Set by the browser: whether the request is same-origin, same-site or cross-site. Pages can't fake it. | cross-site |
X-Forwarded-For | Added by proxies: the original client's IP address. | 203.0.113.7 |
| Header | What it does | Example |
|---|---|---|
Content-Type | Format of the body. Wrong values make browsers refuse scripts or download pages. | text/html; charset=utf-8 |
Content-Encoding | How the body is compressed. | br |
Cache-Control | Who may cache it and for how long. Explained. | public, max-age=31536000, immutable |
ETag | A version tag for the response, used with If-None-Match. | "33a64df5" |
Last-Modified | When the resource last changed. | Tue, 24 Sep 2026 10:00:00 GMT |
Age | Seconds a CDN or proxy has held this copy. Present means it came from a cache. | 412 |
Vary | Which request headers change the response, so caches keep separate copies. | Origin, Accept-Encoding |
Set-Cookie | Stores a cookie. Add Secure, HttpOnly and SameSite. | id=4f2a; Secure; HttpOnly; SameSite=Lax |
Location | Where to go, with a 3xx redirect or 201 Created. | https://example.com/login |
Content-Disposition | Show inline or download, and the file name. | attachment; filename="report.pdf" |
WWW-Authenticate | Sent with 401: how to authenticate. 401 vs 403. | Bearer realm="api" |
Retry-After | With 429 or 503: how long to wait. | 120 |
Server | The server software. Many sites hide or shorten it. | nginx |
These let a page on one origin read responses from another. What CORS is · every CORS error message · preflight requests.
| Header | What it does | Example |
|---|---|---|
Access-Control-Allow-Origin | Which origin may read the response. | https://app.example.com |
Access-Control-Allow-Methods | Methods allowed, in a preflight answer. | GET, POST, PUT, DELETE |
Access-Control-Allow-Headers | Request headers allowed, in a preflight answer. | Content-Type, Authorization |
Access-Control-Allow-Credentials | Whether cookies may be sent and the response read. | true |
Access-Control-Expose-Headers | Response headers page JavaScript may read. | X-Total-Count |
Access-Control-Max-Age | How long the browser may reuse a preflight answer. | 7200 |
| Header | What it does | Example |
|---|---|---|
Strict-Transport-Security | Only ever connect over HTTPS, for this long. | max-age=63072000; includeSubDomains |
Content-Security-Policy | Which sources scripts, styles, images and frames may load from. | default-src 'self'; frame-ancestors 'none' |
X-Frame-Options | Whether other sites may put this page in a frame. Explained. | DENY |
X-Content-Type-Options | Don't guess the file type; trust Content-Type. | nosniff |
Referrer-Policy | How much of the URL to put in Referer. | strict-origin-when-cross-origin |
Permissions-Policy | Which browser features (camera, location...) the page may use. | camera=(), geolocation=() |
Cross-Origin-Opener-Policy | Isolates the page's window from pages it opens. | same-origin |
See: DevTools (F12) → Network → click a request → Headers. From a terminal, curl -I https://example.com shows response headers and curl -v shows both directions. A HAR file records every header of a whole session, and our HAR viewer reads one in your browser.
Change, for testing: curl -H "Name: value" for one-off requests. In the browser, a header extension adds or overrides headers on the sites you choose. See how to add a request header in Chrome.
Set, add or remove any request or response header on the sites you choose, and see whether each rule fired. Unlimited rules, no account, no tracking.
Get HeaderForge for ChromeMore on this topic: “Refused to load … violates the following Content Security Policy directive”: fixes · Mixed content error: “loaded over HTTPS, but requested an insecure resource” · How to change your user agent in Chrome (and what it really changes) · ModHeader alternative