HTTP Headers Table

–20 headers that cover virtually every request and response
HeaderDirectionWhat it does
HostRequestThe domain name of the server - the only HTTP/1.1 mandatory request header
User-AgentRequestBrowser and OS identity string
AcceptRequestContent types the client can process, e.g. application/json
AuthorizationRequestCredentials for HTTP authentication (Bearer tokens, Basic)
CookieRequestPreviously stored cookies sent back to the server
Content-TypeBothThe media type of the body (application/json, text/html, etc.)
Content-LengthBothThe size of the request or response body in bytes
Cache-ControlResponseCaching directives: max-age, no-cache, no-store, public, private
ETagResponseA version identifier for conditional requests (If-None-Match)
LocationResponseThe redirect target URL for 3xx responses
Set-CookieResponseSets a cookie with attributes: HttpOnly, Secure, SameSite
X-Content-Type-OptionsResponsenosniff prevents MIME-type sniffing
X-Frame-OptionsResponseDENY or SAMEORIGIN to prevent clickjacking via iframes
Strict-Transport-SecurityResponseHSTS: forces HTTPS for a max-age period
Access-Control-Allow-OriginResponseCORS: which origins may access the resource
Access-Control-Allow-MethodsResponseCORS: which HTTP methods are permitted
Access-Control-Allow-HeadersResponseCORS: which custom headers are permitted
If-None-MatchRequestSends the stored ETag for cache validation (304 if unchanged)
RefererRequestThe URL of the page that initiated the request
Accept-EncodingRequestCompression algorithms the client supports (gzip, br)
The 20 headers above cover virtually every request and response in real traffic, with semantics verbatim from MDN's HTTP headers reference. Three functional groups organise them: request-only headers (Host, Cookie, Authorization) that clients send; response-only headers (Set-Cookie, ETag, Location) that servers return; and dual headers (Content-Type, Content-Length) that appear in both. Bottom line: the three security headers - Strict-Transport-Security, X-Frame-Options and X-Content-Type-Options - are the cheapest security upgrade a web server can make, and their absence is the first thing a security scan flags. Status codes: HTTP status codes table, methods HTTP methods table, URLs URL parser, CORS depth HTTP status codes table.

HTTP headers carry the metadata of every web request and response - the body is the content, but the headers are the instructions. This table covers the 20 that appear in virtually every real exchange, from Host (mandatory in HTTP/1.1) to the three CORS headers that control cross-origin access.

The security trio - Strict-Transport-Security, X-Frame-Options and X-Content-Type-Options - costs nothing to add and blocks clickjacking, MIME sniffing and protocol downgrade attacks in one response.

How to use

  1. Filter by header name, direction (request/response), or functional group (CORS, caching, security).
  2. Read the direction column: request-only headers come from the client, response-only from the server, and a few appear in both.
  3. Click any header to copy its name for an API doc or a security scan fix.

Frequently asked questions

What is the difference between 401 and 403?

401 Unauthorized means the client has not authenticated (no or invalid credentials in the Authorization header) - the fix is logging in. 403 Forbidden means the server knows who you are and still refuses - the fix is permissions, not credentials. The Authorization header carries Bearer tokens, Basic base64 or API keys.

What does the ETag do?

An ETag is a fingerprint of a resource version. The server sends it with the response; the client stores it and sends it back in If-None-Match on the next request. If the ETag matches, the server returns 304 Not Modified instead of the full body - saving bandwidth for both sides.

Why is SameSite important for cookies?

SameSite=Lax (the browser default) prevents cookies from being sent in cross-site requests, which blocks most CSRF attacks. SameSite=None is required for third-party cookies but needs the Secure flag. SameSite=Strict is the most restrictive: the cookie is only sent when the request originates from the same site.

What is the difference between no-cache and no-store?

no-cache means the browser may store the response but must revalidate with the server before using it (via If-None-Match). no-store means never store at all - used for sensitive data like banking pages. Most dynamic content wants no-cache; only truly private data needs no-store.

Related tools