HTTP headers: a practical list

HTTP headers are the name-value lines at the top of every request and response. There are hundreds; these are the ones you'll actually meet while building or debugging a website, grouped by job, each with what it does and a typical value.

On this page
  1. What headers look like
  2. Request headers
  3. Response headers
  4. CORS headers
  5. Security headers
  6. How to see and change them

What headers look like

GET /api/orders HTTP/1.1
Host: shop.example.com
Accept: application/json
Authorization: Bearer eyJhbGciOi...
Cookie: session=4f2a...

HTTP/1.1 200 OK
Content-Type: application/json; charset=utf-8
Cache-Control: private, no-cache
Set-Cookie: session=4f2a...; Secure; HttpOnly; SameSite=Lax

Names are case-insensitive. HTTP/2 and HTTP/3 send them in lower case, which is why DevTools often shows content-type.

Request headers

HeaderWhat it doesExample
HostWhich site on the server you want. Required in HTTP/1.1.shop.example.com
User-AgentIdentifies the browser or client. See yours.Mozilla/5.0 (Windows NT 10.0; ...) Chrome/129.0
AcceptFormats the client can read, in order of preference.application/json
Accept-LanguagePreferred languages.en-US,en;q=0.9
Accept-EncodingCompression the client supports.gzip, deflate, br, zstd
AuthorizationCredentials, usually a token. Decode a JWT.Bearer eyJhbGciOi...
CookieCookies the browser stored for this site.session=4f2a; theme=dark
Content-TypeFormat of the request body.application/json
Content-LengthSize of the body in bytes.348
RefererThe page the request came from (one r, a historic typo). Explained.https://blog.example.com/
OriginThe origin that started a cross-origin or POST request. Used by CORS and CSRF checks.https://app.example.com
If-None-MatchOnly send the body if the ETag changed; otherwise the server answers 304."33a64df5"
If-Modified-SinceOnly send the body if it changed after this date.Tue, 24 Sep 2026 10:00:00 GMT
Cache-ControlIn a request: asks caches for a fresh copy.no-cache
RangeAsk for part of a file (video seeking, resumed downloads).bytes=0-1023
Sec-Fetch-SiteSet by the browser: whether the request is same-origin, same-site or cross-site. Pages can't fake it.cross-site
X-Forwarded-ForAdded by proxies: the original client's IP address.203.0.113.7

Response headers

HeaderWhat it doesExample
Content-TypeFormat of the body. Wrong values make browsers refuse scripts or download pages.text/html; charset=utf-8
Content-EncodingHow the body is compressed.br
Cache-ControlWho may cache it and for how long. Explained.public, max-age=31536000, immutable
ETagA version tag for the response, used with If-None-Match."33a64df5"
Last-ModifiedWhen the resource last changed.Tue, 24 Sep 2026 10:00:00 GMT
AgeSeconds a CDN or proxy has held this copy. Present means it came from a cache.412
VaryWhich request headers change the response, so caches keep separate copies.Origin, Accept-Encoding
Set-CookieStores a cookie. Add Secure, HttpOnly and SameSite.id=4f2a; Secure; HttpOnly; SameSite=Lax
LocationWhere to go, with a 3xx redirect or 201 Created.https://example.com/login
Content-DispositionShow inline or download, and the file name.attachment; filename="report.pdf"
WWW-AuthenticateSent with 401: how to authenticate. 401 vs 403.Bearer realm="api"
Retry-AfterWith 429 or 503: how long to wait.120
ServerThe server software. Many sites hide or shorten it.nginx

CORS headers

These let a page on one origin read responses from another. What CORS is · every CORS error message · preflight requests.

HeaderWhat it doesExample
Access-Control-Allow-OriginWhich origin may read the response.https://app.example.com
Access-Control-Allow-MethodsMethods allowed, in a preflight answer.GET, POST, PUT, DELETE
Access-Control-Allow-HeadersRequest headers allowed, in a preflight answer.Content-Type, Authorization
Access-Control-Allow-CredentialsWhether cookies may be sent and the response read.true
Access-Control-Expose-HeadersResponse headers page JavaScript may read.X-Total-Count
Access-Control-Max-AgeHow long the browser may reuse a preflight answer.7200

Security headers

HeaderWhat it doesExample
Strict-Transport-SecurityOnly ever connect over HTTPS, for this long.max-age=63072000; includeSubDomains
Content-Security-PolicyWhich sources scripts, styles, images and frames may load from.default-src 'self'; frame-ancestors 'none'
X-Frame-OptionsWhether other sites may put this page in a frame. Explained.DENY
X-Content-Type-OptionsDon't guess the file type; trust Content-Type.nosniff
Referrer-PolicyHow much of the URL to put in Referer.strict-origin-when-cross-origin
Permissions-PolicyWhich browser features (camera, location...) the page may use.camera=(), geolocation=()
Cross-Origin-Opener-PolicyIsolates the page's window from pages it opens.same-origin

How to see and change them

See: DevTools (F12) → Network → click a request → Headers. From a terminal, curl -I https://example.com shows response headers and curl -v shows both directions. A HAR file records every header of a whole session, and our HAR viewer reads one in your browser.

Change, for testing: curl -H "Name: value" for one-off requests. In the browser, a header extension adds or overrides headers on the sites you choose. See how to add a request header in Chrome.

HeaderForge (Chrome, free)

Set, add or remove any request or response header on the sites you choose, and see whether each rule fired. Unlimited rules, no account, no tracking.

Get HeaderForge for Chrome

More on this topic: “Refused to load … violates the following Content Security Policy directive”: fixes · Mixed content error: “loaded over HTTPS, but requested an insecure resource” · How to change your user agent in Chrome (and what it really changes) · ModHeader alternative