HTTP Headers Table
| Header | Direction | What it does |
|---|---|---|
| Host | Request | The domain name of the server - the only HTTP/1.1 mandatory request header |
| User-Agent | Request | Browser and OS identity string |
| Accept | Request | Content types the client can process, e.g. application/json |
| Authorization | Request | Credentials for HTTP authentication (Bearer tokens, Basic) |
| Cookie | Request | Previously stored cookies sent back to the server |
| Content-Type | Both | The media type of the body (application/json, text/html, etc.) |
| Content-Length | Both | The size of the request or response body in bytes |
| Cache-Control | Response | Caching directives: max-age, no-cache, no-store, public, private |
| ETag | Response | A version identifier for conditional requests (If-None-Match) |
| Location | Response | The redirect target URL for 3xx responses |
| Set-Cookie | Response | Sets a cookie with attributes: HttpOnly, Secure, SameSite |
| X-Content-Type-Options | Response | nosniff prevents MIME-type sniffing |
| X-Frame-Options | Response | DENY or SAMEORIGIN to prevent clickjacking via iframes |
| Strict-Transport-Security | Response | HSTS: forces HTTPS for a max-age period |
| Access-Control-Allow-Origin | Response | CORS: which origins may access the resource |
| Access-Control-Allow-Methods | Response | CORS: which HTTP methods are permitted |
| Access-Control-Allow-Headers | Response | CORS: which custom headers are permitted |
| If-None-Match | Request | Sends the stored ETag for cache validation (304 if unchanged) |
| Referer | Request | The URL of the page that initiated the request |
| Accept-Encoding | Request | Compression algorithms the client supports (gzip, br) |
HTTP headers carry the metadata of every web request and response - the body is the content, but the headers are the instructions. This table covers the 20 that appear in virtually every real exchange, from Host (mandatory in HTTP/1.1) to the three CORS headers that control cross-origin access.
The security trio - Strict-Transport-Security, X-Frame-Options and X-Content-Type-Options - costs nothing to add and blocks clickjacking, MIME sniffing and protocol downgrade attacks in one response.
How to use
- Filter by header name, direction (request/response), or functional group (CORS, caching, security).
- Read the direction column: request-only headers come from the client, response-only from the server, and a few appear in both.
- Click any header to copy its name for an API doc or a security scan fix.
Frequently asked questions
What is the difference between 401 and 403?
401 Unauthorized means the client has not authenticated (no or invalid credentials in the Authorization header) - the fix is logging in. 403 Forbidden means the server knows who you are and still refuses - the fix is permissions, not credentials. The Authorization header carries Bearer tokens, Basic base64 or API keys.
What does the ETag do?
An ETag is a fingerprint of a resource version. The server sends it with the response; the client stores it and sends it back in If-None-Match on the next request. If the ETag matches, the server returns 304 Not Modified instead of the full body - saving bandwidth for both sides.
Why is SameSite important for cookies?
SameSite=Lax (the browser default) prevents cookies from being sent in cross-site requests, which blocks most CSRF attacks. SameSite=None is required for third-party cookies but needs the Secure flag. SameSite=Strict is the most restrictive: the cookie is only sent when the request originates from the same site.
What is the difference between no-cache and no-store?
no-cache means the browser may store the response but must revalidate with the server before using it (via If-None-Match). no-store means never store at all - used for sensitive data like banking pages. Most dynamic content wants no-cache; only truly private data needs no-store.